Atomicorp WAF Research Notes
Research Update - 2026-09-26
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-100382 | Unauthenticated remote code execution through wikitext in ExternalData | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-88414 | MCMS 6.1.1 through 6.2.1 SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-65950 | WBCE CMS is Vulnerable to Time-Based Blind SQL Injection through groups[] Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-34162 | Bian Que Feijiu Intelligent Emergency and Quality Control System SQL Injection via GetLyfsByParams | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-39353 | InvoicePlane: Remote Code Execution via Writable Templates Directory | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-62262 | Piwigo: Unauthenticated SQL injection in pwg.images.filteredSearch.create | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-51457 | D-Link DAP-2610 up to 2.06B08r099 Command Injection Vulnerability | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2025-66295 | Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corrupti | 344360 |
| CVE-2025-9216 | StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.5.0 - Authent | 351000 |
| CVE-2026-100391 | MediaFlow Proxy through 2.4.9 Server-Side Request Forgery via Incomplete Validation | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-61525 | Zammad: Arbitrary File Deletion via Unvalidated Session Identifier in Long Polling Controller | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-65660 | Microsoft SharePoint Server Remote Code Execution Vulnerability | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-96795 | Horilla: Authenticated RCE in Horilla List-View Export | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2025-34311 | IPFire < v2.29 Command Injection via Proxy Report Creation | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390716 , 393655 |
| CVE-2025-34312 | IPFire < v2.29 Command Injection via URL Filter Blacklist | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2025-41013 | SQL injection vulnerability in TCMAN GIM | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-66474 | XWiki vulnerable to remote code execution through insufficient protection against {{/html}} injection | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-100520 | Laranode before 1.2.1 Path Traversal in File Manager Upload Endpoint | 340007 , 344360 , 390709 |
| CVE-2026-100372 | ClipBucket v5 before 5.5.3-#197 Path Traversal via template_editor.php | 340007 , 344360 , 347009 , 390709 |
| CVE-2025-66300 | Grav is vulnerable to Arbitrary File Read | 344360 |
| CVE-2026-100172 | Stored XSS in AIL Framework extracted-match popovers via unescaped dynamic values in HTML-enabled data-content attribute | 333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-100176 | Stored Cross-Site Scripting (XSS) in AIL Framework Username Timeline Tooltip | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-71483 | Horilla: Reflected Cross-Site Scripting (XSS) in Employee Filter View | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-65879 | warehouse management system Path Traversal Vulnerability | 340007 , 344360 , 390709 |
| CVE-2025-9990 | WordPress Helpdesk Integration <= 5.8.10 - Unauthenticated Local File Inclusion | 340748 , 344360 , 347006 , 347009 , 390709 |
| CVE-2026-44642 | Piwigo: SQL injection in upgrade authentication allows unauthenticated upgrade authorization bypass (PHP 8+) | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-51773 | Security Vulnerability | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-97875 | DNS rebinding vulnerability in rojo serve HTTP API | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2025-65878 | warehouse management system Path Traversal Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-50547 | InvoicePlane permits local file inclusion through the e-invoice XML configuration identifier | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-67237 | RabbitMQ: Reflected XSS via the OAuth bootstrap JS endpoint | 333140 , 333141 , 340099 , 341099 , 342259 , 346755 |
| CVE-2025-48868 | Horilla vulnerable to authenticated RCE via eval() in project_bulk_archive | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-42323 | Piwigo: SQL Injection in Batch Manager | 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-42324 | Piwigo: Second-Order SQL Injection | 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-93654 | Premium Packages <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-13072 | HandL UTM Grabber / Tracker < 2.8.1 - Reflected XSS via utm_source | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2025-13073 | HandL UTM Grabber / Tracker < 2.8.1 - Reflected XSS via handl_landing_page | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-14701 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafty Controller | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 344370 , 346755 , 350147 , 350148 |
| CVE-2025-10597 | kidaze CourseSelectionSystem COUNT2.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-43779 | digital experience platform Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-97865 | Open-Web-Analytics Remote Event Queue Endpoint queue.php loadFromArray deserialization | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 |
| CVE-2025-66302 | Grav vulnerable to Path Traversal allowing server files backup | 344360 |
| CVE-2025-51969 | online shopping system advanced SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-63432 | Horilla: Server-Side Template Injection (SSTI) in Mail Preview Endpoints Allows Authenticated Users to Disclose Password | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-100190 | Stored Cross-Site Scripting (XSS) via Crawler Capture Import in AIL Framework showDomain Page | 333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-66311 | Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint /admin/pages/[page] in Multiples parameters | 333140 , 333141 |
| CVE-2025-66312 | Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint /admin/accounts/groups/[group] parameter `d | 333140 , 333141 , 340147 , 340148 , 342259 , 346755 |
| CVE-2026-78902 | Netgate pfSense 26.03.1-RELEASE Arbitrary Code Execution Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-54790 | InvoicePlane: Second-order SQL injection through the unvalidated custom_field_table field in the Custom Fields module | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-10596 | SourceCodester Online Exam Form Submission index.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-10598 | SourceCodester Pet Grooming Management Software search_product.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-10599 | itsourcecode Web-Based Internet Laboratory Management System login.php AuthenticateUser sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-10600 | SourceCodester Online Exam Form Submission register.php unrestricted upload | 351000 |
| CVE-2025-10601 | SourceCodester Online Exam Form Submission index.php sql injection | 340017 , 340145 , 340156 , 340457 , 341245 , 360147 , 360148 , 370016 , 380026 , 380122 , 390572 |
| CVE-2025-10621 | SourceCodester Hotel Reservation System editroomimage.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-10623 | SourceCodester Hotel Reservation System deleteuser.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-10624 | PHPGurukul User Management System login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-9592 | itsourcecode Apartment Management System bill_info.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-9593 | itsourcecode Apartment Management System unit_status_info.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-9594 | itsourcecode Apartment Management System complain_info.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-9765 | itsourcecode Sports Management System tournament_details.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-9766 | itsourcecode Sports Management System facilitator.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-9767 | itsourcecode Sports Management System sporttype.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-97882 | mathurvishal CloudClassroom-PHP-Project Faculty Authentication loginlinkfaculty.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-97883 | mathurvishal CloudClassroom-PHP-Project updatequery.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-97885 | mathurvishal CloudClassroom-PHP-Project updatefaculty.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-34425 | MailEnable < 10.54 Reflected XSS in WindowContext Parameter of MAI/compose.aspx | 333140 , 333141 , 340099 , 340147 , 341099 , 341256 , 341266 , 346755 |
| CVE-2025-66460 | Lookyloo vulnerable to XSS due to lack of escaping in HTML elements passed to Datatables | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-100381 | UploadWizard Flickr collection and set titles allow DOM XSS | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2025-34257 | Advantech WISE-DeviceOn Server < 5.4 Authenticated Stored XSS via action/defined | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-34315 | IPFire < v2.29 Stored XSS via Remote Syslog Server Address | 333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 390716 |
| CVE-2025-34316 | IPFire < v2.29 Stored XSS via Mail Server Settings | 346755 |
| CVE-2025-34318 | IPFire < v2.29 Stored XSS via DNS Creation (proxy.cgi) | 333140 , 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-40725 | Reflected Cross-Site Scripting (XSS) in Azon Dominator | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 , 350147 , 350148 |
| CVE-2026-100174 | Stored Cross-Site Scripting (XSS) in AIL Framework Tag Selector via Unescaped Tag Names | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-100373 | OpenMetadata through 2.0.2 SSRF via Webhook URL Validation Bypass | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-100521 | Cotonti through 1.0.0 Reflected XSS via search highlight parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-100522 | Cotonti through 1.0.0 Reflected XSS via message.php lng parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-100523 | Cotonti through 1.0.0 Open Redirect via message.php redirect parameter | 344365 |
| CVE-2026-6082 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-6083 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-6084 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-6085 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-6086 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-6087 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-6088 | Stored Cross-Site Scripting in StockAgile by Novadigits technologies | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-100376 | TemplateSandbox can be abused for XSS by asking another user to preview a page with a certain sandbox prefix | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-85293 | InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer Forms | 333140 , 333141 , 340095 , 340099 , 340147 , 340148 , 340149 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-10232 | 299ko FileManagerAPIController.php delete path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2025-10233 | kalcaddle kodbox editor.class.php fileSave path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2025-10590 | Portabilis i-Educar educar_usuario_det.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-10593 | SourceCodester Online Student File Management System update_student.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-10594 | SourceCodester Online Student File Management System delete_student.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-10595 | SourceCodester Online Student File Management System delete_user.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-10602 | SourceCodester Online Exam Form Submission delete_s1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-10605 | Portabilis i-Educar agenda_preferencias.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-10613 | itsourcecode Student Information System leveledit1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-10614 | itsourcecode E-Logbook with Health Monitoring System for COVID-19 print_reports_prev.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-10625 | SourceCodester Online Exam Form Submission dashboard.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-97886 | mathurvishal CloudClassroom-PHP-Project managevideos2.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2025-10584 | Portabilis i-Educar educar_calendario_anotacao_cad.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-10591 | Portabilis i-Educar Editar Função educar_funcao_cad.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-14006 | dayrui XunRuiCMS Add Data Validation admind45f74adbd95.php cross site scripting | 333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2025-14116 | xerrors Yuxi-Know embed.py OtherEmbedding.aencode server-side request forgery | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-97896 | krayin laravel-crm Upload Functionality ConfigurationForm.php rules cross site scripting | 333140 , 333141 , 340095 , 340148 , 350148 |
| CVE-2025-9591 | ZrLog Theme Configuration Form config cross site scripting | 333140 , 333141 , 340095 |
| CVE-2025-14007 | dayrui XunRuiCMS Domain Name Binding admin79f2ec220c7e.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |