Atomicorp WAF Research Notes

Research Update - 2026-09-26

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-100382Unauthenticated remote code execution through wikitext in ExternalData340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-88414MCMS 6.1.1 through 6.2.1 SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-65950WBCE CMS is Vulnerable to Time-Based Blind SQL Injection through groups[] Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-34162Bian Que Feijiu Intelligent Emergency and Quality Control System SQL Injection via GetLyfsByParams340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-39353InvoicePlane: Remote Code Execution via Writable Templates Directory340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-62262Piwigo: Unauthenticated SQL injection in pwg.images.filteredSearch.create340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-51457D-Link DAP-2610 up to 2.06B08r099 Command Injection Vulnerability340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2025-66295Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corrupti344360
CVE-2025-9216StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.5.0 - Authent351000
CVE-2026-100391MediaFlow Proxy through 2.4.9 Server-Side Request Forgery via Incomplete Validation337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-61525Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Polling Controller340007 , 344360 , 347009 , 390709
CVE-2026-65660Microsoft SharePoint Server Remote Code Execution Vulnerability340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-96795Horilla: Authenticated RCE in Horilla List-View Export340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2025-34311IPFire < v2.29 Command Injection via Proxy Report Creation340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390716 , 393655
CVE-2025-34312IPFire < v2.29 Command Injection via URL Filter Blacklist340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2025-41013SQL injection vulnerability in TCMAN GIM340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-66474XWiki vulnerable to remote code execution through insufficient protection against {{/html}} injection340014 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-100520Laranode before 1.2.1 Path Traversal in File Manager Upload Endpoint340007 , 344360 , 390709
CVE-2026-100372ClipBucket v5 before 5.5.3-#197 Path Traversal via template_editor.php340007 , 344360 , 347009 , 390709
CVE-2025-66300Grav is vulnerable to Arbitrary File Read344360
CVE-2026-100172Stored XSS in AIL Framework extracted-match popovers via unescaped dynamic values in HTML-enabled data-content attribute333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-100176Stored Cross-Site Scripting (XSS) in AIL Framework Username Timeline Tooltip333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-71483Horilla: Reflected Cross-Site Scripting (XSS) in Employee Filter View333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-65879warehouse management system Path Traversal Vulnerability340007 , 344360 , 390709
CVE-2025-9990WordPress Helpdesk Integration <= 5.8.10 - Unauthenticated Local File Inclusion340748 , 344360 , 347006 , 347009 , 390709
CVE-2026-44642Piwigo: SQL injection in upgrade authentication allows unauthenticated upgrade authorization bypass (PHP 8+)340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-51773Security Vulnerability337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-97875DNS rebinding vulnerability in rojo serve HTTP API340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2025-65878warehouse management system Path Traversal Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-50547InvoicePlane permits local file inclusion through the e-invoice XML configuration identifier340007 , 344360 , 347009 , 390709
CVE-2026-67237RabbitMQ: Reflected XSS via the OAuth bootstrap JS endpoint333140 , 333141 , 340099 , 341099 , 342259 , 346755
CVE-2025-48868Horilla vulnerable to authenticated RCE via eval() in project_bulk_archive340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-42323Piwigo: SQL Injection in Batch Manager340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-42324Piwigo: Second-Order SQL Injection340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-93654Premium Packages <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2025-13072HandL UTM Grabber / Tracker < 2.8.1 - Reflected XSS via utm_source333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2025-13073HandL UTM Grabber / Tracker < 2.8.1 - Reflected XSS via handl_landing_page333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-14701Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafty Controller333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 344370 , 346755 , 350147 , 350148
CVE-2025-10597kidaze CourseSelectionSystem COUNT2.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-43779digital experience platform Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-97865Open-Web-Analytics Remote Event Queue Endpoint queue.php loadFromArray deserialization340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722
CVE-2025-66302Grav vulnerable to Path Traversal allowing server files backup344360
CVE-2025-51969online shopping system advanced SQL Injection Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-63432Horilla: Server-Side Template Injection (SSTI) in Mail Preview Endpoints Allows Authenticated Users to Disclose Password340014 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-100190Stored Cross-Site Scripting (XSS) via Crawler Capture Import in AIL Framework showDomain Page333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2025-66311Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint /admin/pages/[page] in Multiples parameters333140 , 333141
CVE-2025-66312Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint /admin/accounts/groups/[group] parameter `d333140 , 333141 , 340147 , 340148 , 342259 , 346755
CVE-2026-78902Netgate pfSense 26.03.1-RELEASE Arbitrary Code Execution Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-54790InvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field in the Custom Fields module340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-10596SourceCodester Online Exam Form Submission index.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-10598SourceCodester Pet Grooming Management Software search_product.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-10599itsourcecode Web-Based Internet Laboratory Management System login.php AuthenticateUser sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-10600SourceCodester Online Exam Form Submission register.php unrestricted upload351000
CVE-2025-10601SourceCodester Online Exam Form Submission index.php sql injection340017 , 340145 , 340156 , 340457 , 341245 , 360147 , 360148 , 370016 , 380026 , 380122 , 390572
CVE-2025-10621SourceCodester Hotel Reservation System editroomimage.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-10623SourceCodester Hotel Reservation System deleteuser.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-10624PHPGurukul User Management System login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-9592itsourcecode Apartment Management System bill_info.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-9593itsourcecode Apartment Management System unit_status_info.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-9594itsourcecode Apartment Management System complain_info.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-9765itsourcecode Sports Management System tournament_details.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-9766itsourcecode Sports Management System facilitator.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-9767itsourcecode Sports Management System sporttype.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-97882mathurvishal CloudClassroom-PHP-Project Faculty Authentication loginlinkfaculty.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-97883mathurvishal CloudClassroom-PHP-Project updatequery.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-97885mathurvishal CloudClassroom-PHP-Project updatefaculty.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-34425MailEnable < 10.54 Reflected XSS in WindowContext Parameter of MAI/compose.aspx333140 , 333141 , 340099 , 340147 , 341099 , 341256 , 341266 , 346755
CVE-2025-66460Lookyloo vulnerable to XSS due to lack of escaping in HTML elements passed to Datatables333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-100381UploadWizard Flickr collection and set titles allow DOM XSS333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2025-34257Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/defined333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2025-34315IPFire < v2.29 Stored XSS via Remote Syslog Server Address333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 390716
CVE-2025-34316IPFire < v2.29 Stored XSS via Mail Server Settings346755
CVE-2025-34318IPFire < v2.29 Stored XSS via DNS Creation (proxy.cgi)333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2025-40725Reflected Cross-Site Scripting (XSS) in Azon Dominator333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 , 350147 , 350148
CVE-2026-100174Stored Cross-Site Scripting (XSS) in AIL Framework Tag Selector via Unescaped Tag Names333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-100373OpenMetadata through 2.0.2 SSRF via Webhook URL Validation Bypass337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-100521Cotonti through 1.0.0 Reflected XSS via search highlight parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-100522Cotonti through 1.0.0 Reflected XSS via message.php lng parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-100523Cotonti through 1.0.0 Open Redirect via message.php redirect parameter344365
CVE-2026-6082Stored Cross-Site Scripting in StockAgile by Novadigits technologies333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-6083Stored Cross-Site Scripting in StockAgile by Novadigits technologies333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-6084Stored Cross-Site Scripting in StockAgile by Novadigits technologies333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-6085Stored Cross-Site Scripting in StockAgile by Novadigits technologies333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-6086Stored Cross-Site Scripting in StockAgile by Novadigits technologies333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2026-6087Stored Cross-Site Scripting in StockAgile by Novadigits technologies333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-6088Stored Cross-Site Scripting in StockAgile by Novadigits technologies333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-100376TemplateSandbox can be abused for XSS by asking another user to preview a page with a certain sandbox prefix333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-85293InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer Forms333140 , 333141 , 340095 , 340099 , 340147 , 340148 , 340149 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-10232299ko FileManagerAPIController.php delete path traversal340007 , 344360 , 347009 , 390709
CVE-2025-10233kalcaddle kodbox editor.class.php fileSave path traversal340007 , 344360 , 347009 , 390709
CVE-2025-10590Portabilis i-Educar educar_usuario_det.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-10593SourceCodester Online Student File Management System update_student.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-10594SourceCodester Online Student File Management System delete_student.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-10595SourceCodester Online Student File Management System delete_user.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-10602SourceCodester Online Exam Form Submission delete_s1.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-10605Portabilis i-Educar agenda_preferencias.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2025-10613itsourcecode Student Information System leveledit1.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-10614itsourcecode E-Logbook with Health Monitoring System for COVID-19 print_reports_prev.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-10625SourceCodester Online Exam Form Submission dashboard.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-97886mathurvishal CloudClassroom-PHP-Project managevideos2.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2025-10584Portabilis i-Educar educar_calendario_anotacao_cad.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2025-10591Portabilis i-Educar Editar Função educar_funcao_cad.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-14006dayrui XunRuiCMS Add Data Validation admind45f74adbd95.php cross site scripting333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755
CVE-2025-14116xerrors Yuxi-Know embed.py OtherEmbedding.aencode server-side request forgery337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-97896krayin laravel-crm Upload Functionality ConfigurationForm.php rules cross site scripting333140 , 333141 , 340095 , 340148 , 350148
CVE-2025-9591ZrLog Theme Configuration Form config cross site scripting333140 , 333141 , 340095
CVE-2025-14007dayrui XunRuiCMS Domain Name Binding admin79f2ec220c7e.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148