Atomicorp WAF Research Notes
Research Update - 2026-09-21
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-94104 | NivoCart through 2.4.0 Arbitrary File Upload RCE via filemanager | 351000 |
| CVE-2026-93972 | SourceCodester Online Reviewer Management System btn_functions.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-93973 | SourceCodester Online Reviewer Management System btn_functions.php remove sql injection | 340016 , 340017 , 340145 , 340156 , 341145 , 341245 , 380026 , 380122 , 390572 |
| CVE-2026-93974 | SourceCodester Online Reviewer Management System btn_functions.php remove sql injection | 340016 , 340017 , 340145 , 340156 , 341145 , 341245 , 380026 , 380122 , 390572 |
| CVE-2026-93978 | code-projects Internship Management System login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-93979 | code-projects Internship Management System login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-93980 | code-projects Internship Management System Admin Login Form login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-93997 | SourceCodester Drug Recommendation System edit_symptom.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-94015 | SourceCodester Drug Recommendation System edit_user.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-94038 | NonceGeek dim-sum-app Deno Backend main.tsx textSearchV2Handler server-side request forgery | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-94039 | vas3k TaxHacker Invoice PDF Renderer actions.ts generateInvoicePDF server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-94040 | vas3k TaxHacker actions.ts testLLMProviderAction server-side request forgery | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-94044 | 03-lovepreetSingh MCP route.ts create_file path traversal | 340007 , 344360 , 390709 |
| CVE-2026-94110 | QCMS Content Detail Controllers.php self_Tmp sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-94028 | mealie-recipes Mealie Recipe Action Trigger controller_group_recipe_actions.py payload.model_dump server-side request fo | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-94032 | itsourcecode Leave Management System index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-94035 | SourceCodester Drug Recommendation System index.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-94041 | AdithyaYelloju Restaurant-Management-System add_menu.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-94042 | AdithyaYelloju Restaurant Management System add_table.php mysqli_query sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-94046 | 0215AndrewFeng ACE-MCP MCP Tool getFileSnippet.ts get_file_snippet path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-94049 | 06ketan slideshot renderer.ts render_slides path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-94102 | WuzhiCMS Login index.php redirect | 340162 , 340163 , 340165 , 344365 |
| CVE-2026-93977 | code-projects Assessment Management add-single-mark.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-94033 | SourceCodester Drug Recommendation System User Management add_user cross site scripting | 346755 |
| CVE-2026-94034 | SourceCodester Drug Recommendation System Password Change change_password cross site scripting | 346755 |
| CVE-2026-94103 | RooCMS Frontend Rendering site_pagePHP.php eval code injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-93975 | code-projects Assessment Management User Editing edit-user.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-93976 | code-projects Assessment Management add-user.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-94016 | SourceCodester Drug Recommendation System add_symptom cross site scripting | 346755 |