Atomicorp WAF Research Notes
Research Update - 2026-09-27
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2024-13981 | LiveBos UploadFile.do Arbitrary File Upload | 351000 |
| CVE-2024-13984 | Qi'anxin TianQing Management Center rptsvr Arbitrary File Upload | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2024-13342 | Booster for WooCommerce <= 7.2.4 - Unauthenticated Double Extension Arbitrary File Upload | 351000 |
| CVE-2024-32641 | Masa CMS Vulnerable to Pre-Auth RCE via JSON API | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-100714 | Froxlor before 2.3.12 Command Injection via letsencryptchallengepath | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-100720 | Froxlor before 2.3.12 Stored XSS via SSL certificate issuer | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-100683 | Budibase before 3.45.0 SQL Injection via column-rename DDL | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2023-54359 | WordPress adivaha Travel Plugin 2.3 SQL Injection via pid | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2024-58276 | Obi08-Enrollment System 1.0 login.php SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122 , 390572 |
| CVE-2026-100644 | SiYuan before v3.8.4 SQL Injection via dailyNoteSavePath | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-100682 | Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink | 340007 , 344360 , 390709 |
| CVE-2026-100852 | AzuraCast through 0.23.x Command Injection via Streamer Username | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-100856 | AzuraCast before 0.23.6 Code Injection via Remote Relay Password | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-100864 | heym before 0.0.91 Remote Code Execution via Expression Engine | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-100645 | SiYuan 3.7.0 before 3.8.4 Stored XSS via Gallery Kanban | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-100643 | SiYuan before v3.8.4 Stored XSS via Attribute View textarea | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-100673 | Grav Data Manager before 1.4.5 Stored XSS via item-detail view | 333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755 |
| CVE-2026-100858 | heym before 0.0.109 Server-Side Request Forgery via Workflow Nodes | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-100849 | AzuraCast before 0.23.8 SSRF Filter Bypass via Hostname and Private IPs | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-100859 | Heym before 0.0.106 Credential Exfiltration via URL Override | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-100601 | ClawHub SSRF via Unchecked DNS Resolution in Profile Image | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-100696 | Adminer before 6.0.2 Unauthenticated SSRF via Elasticsearch Driver | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2025-47828 | H5P-Nodejs-library Security Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 346755 |
| CVE-2026-100681 | Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-100314 | mathurvishal CloudClassroom-PHP-Project updatedetailsfromstudent.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-100315 | mathurvishal CloudClassroom-PHP-Project mydetailsfaculty.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-100739 | mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-100697 | Adminer 6.0.0 Server-Side Request Forgery via ClickHouse driver | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-100861 | heym before 0.0.105 SSRF via credential-controlled base URLs | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2023-54358 | WordPress adivaha Travel Plugin 2.3 Reflected XSS via isMobile | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2023-54361 | Joomla iProperty Real Estate 4.1.1 Reflected XSS via filter_keyword | 333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2023-54362 | Joomla VirtueMart Shopping-Cart 4.0.12 Reflected XSS via keyword | 333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-100630 | AVideo Stored XSS via HTML Entity Bypass in trailer1 Field | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-100850 | AzuraCast before 0.23.8 SSRF and Local File Read via Remote Playlist | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-100312 | mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-100313 | mathurvishal CloudClassroom-PHP-Project updatequery.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-84069 | WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-96896 | Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deletion via wpmr_ajax_request | 340014 , 340023 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 360029 , 390904 |