Atomicorp WAF Research Notes
Research Update - 2026-09-18
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-85688 | TEN Framework - Arbitrary File Read & Write | 344360 , 390709 |
| CVE-2026-54670 | WeGIA: Unauthenticated Auth Bypass + Local File Inclusion | 340007 , 344360 , 390709 |
| CVE-2026-45143 | Chamilo LMS: Student-to-admin stored XSS in private messages via v-html | 333140 |
| CVE-2026-47252 | Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrome, Edge, Reminders, Safari) | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-63459 | Vendure: Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions | 333140 , 333141 |
| CVE-2026-92970 | HUBzero CMS through 2.2.32 Path Traversal via File Upload | 340007 , 344360 , 390709 |
| CVE-2026-92985 | SiYuan before 3.8.4 Cross-Site Scripting via Bookmark Labels | 333140 , 333141 , 334168 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-92986 | SiYuan before 3.8.4 Cross-Site Scripting via Document Title | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-54507 | Vvveb oEmbedProxy vulnerable to server-side request forgery | 337109 , 337110 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-93292 | SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-93426 | SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-54597 | ITFlow: Authenticated Time-Based Blind SQL Injection in ITFlow via expires Parameter | 340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122 |
| CVE-2026-54253 | TS3 Manager: Reflected XSS via /api/download port parameter steals operator session | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-54354 | MapServer: PostGIS Numeric Filter Value SQL Injection in MapServer Runtime Query Translation | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-54596 | ITFlow: Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-53557 | SQLBot: Second-Order SQL Injection via Excel Datasource Leading to Remote Command Execution | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-54339 | Glean: Server-Side Request Forgery (SSRF) with Full Response Disclosure via Malicious RSS Feed in /api/feeds/discover | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-54506 | Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field | 333140 , 333141 , 340095 , 340147 , 340148 , 340247 , 340248 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-53534 | JabRef CAYW Sublime Text integration permits operating-system command injection | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-53554 | SQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Import Processing | 340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-54646 | CubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.inc.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 380026 , 380122 , 390572 |
| CVE-2026-54647 | CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-92919 | admin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Upload Filename | 340007 , 344360 , 390709 |
| CVE-2026-93014 | RosarioSIS before 12.9 Path Traversal in File Deletion via filename Parameter | 344360 , 347009 , 390709 |
| CVE-2026-61793 | Nuxt OG Image has unauthenticated SSRF via fonts[].path URL parameter | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-17576 | InfiniteWP Client <= 1.13.9 - Authenticated (Admin+) SQL Injection via 'iwp_get_comments_*' Array Key | 340017 , 340144 , 340156 , 360147 , 360148 , 380122 |
| CVE-2026-51133 | za-internet GmbH C-MOR Video Surveillance <= V6.0104 Arbitrary Code Execution Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-53556 | SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary File Read | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-92926 | code-projects Matrimonial System partner_preference.php writepartnerprefs sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-54613 | Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parameter | 344360 , 347009 |
| CVE-2026-53555 | Stored XSS via SVG Upload | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-56281 | Capgo - SQL Injection via Unvalidated limit Parameter in Admin Stats Endpoint | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-54546 | CloudTAK: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-54645 | CubeCart: Stored XSS in Product Description Editor via Global Sanitizer Bypass | 333140 , 333141 |
| CVE-2026-92993 | Dromara mayfly-go Machine Script Feature machine_script.go RunMachineScript os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |