Atomicorp WAF Research Notes

Research Update - 2026-09-21

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-94104NivoCart through 2.4.0 Arbitrary File Upload RCE via filemanager351000
CVE-2026-93972SourceCodester Online Reviewer Management System btn_functions.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-93973SourceCodester Online Reviewer Management System btn_functions.php remove sql injection340016 , 340017 , 340145 , 340156 , 341145 , 341245 , 380026 , 380122 , 390572
CVE-2026-93974SourceCodester Online Reviewer Management System btn_functions.php remove sql injection340016 , 340017 , 340145 , 340156 , 341145 , 341245 , 380026 , 380122 , 390572
CVE-2026-93978code-projects Internship Management System login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-93979code-projects Internship Management System login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-93980code-projects Internship Management System Admin Login Form login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-93997SourceCodester Drug Recommendation System edit_symptom.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-94015SourceCodester Drug Recommendation System edit_user.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-94038NonceGeek dim-sum-app Deno Backend main.tsx textSearchV2Handler server-side request forgery337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-94039vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-94040vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-9404403-lovepreetSingh MCP route.ts create_file path traversal340007 , 344360 , 390709
CVE-2026-94110QCMS Content Detail Controllers.php self_Tmp sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-94028mealie-recipes Mealie Recipe Action Trigger controller_group_recipe_actions.py payload.model_dump server-side request fo337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-94032itsourcecode Leave Management System index.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-94035SourceCodester Drug Recommendation System index.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-94041AdithyaYelloju Restaurant-Management-System add_menu.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-94042AdithyaYelloju Restaurant Management System add_table.php mysqli_query sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-940460215AndrewFeng ACE-MCP MCP Tool getFileSnippet.ts get_file_snippet path traversal340007 , 344360 , 347009 , 390709
CVE-2026-9404906ketan slideshot renderer.ts render_slides path traversal340007 , 344360 , 347009 , 390709
CVE-2026-94102WuzhiCMS Login index.php redirect340162 , 340163 , 340165 , 344365
CVE-2026-93977code-projects Assessment Management add-single-mark.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-94033SourceCodester Drug Recommendation System User Management add_user cross site scripting346755
CVE-2026-94034SourceCodester Drug Recommendation System Password Change change_password cross site scripting346755
CVE-2026-94103RooCMS Frontend Rendering site_pagePHP.php eval code injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-93975code-projects Assessment Management User Editing edit-user.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2026-93976code-projects Assessment Management add-user.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-94016SourceCodester Drug Recommendation System add_symptom cross site scripting346755