Atomicorp WAF Research Notes

Research Update - 2026-09-27

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2024-13981LiveBos UploadFile.do Arbitrary File Upload351000
CVE-2024-13984Qi'anxin TianQing Management Center rptsvr Arbitrary File Upload340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2024-13342Booster for WooCommerce <= 7.2.4 - Unauthenticated Double Extension Arbitrary File Upload351000
CVE-2024-32641Masa CMS Vulnerable to Pre-Auth RCE via JSON API340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-100714Froxlor before 2.3.12 Command Injection via letsencryptchallengepath340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-100720Froxlor before 2.3.12 Stored XSS via SSL certificate issuer333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-100683Budibase before 3.45.0 SQL Injection via column-rename DDL340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2023-54359WordPress adivaha Travel Plugin 2.3 SQL Injection via pid340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2024-58276Obi08-Enrollment System 1.0 login.php SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122 , 390572
CVE-2026-100644SiYuan before v3.8.4 SQL Injection via dailyNoteSavePath340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-100682Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink340007 , 344360 , 390709
CVE-2026-100852AzuraCast through 0.23.x Command Injection via Streamer Username340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-100856AzuraCast before 0.23.6 Code Injection via Remote Relay Password340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-100864heym before 0.0.91 Remote Code Execution via Expression Engine340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-100645SiYuan 3.7.0 before 3.8.4 Stored XSS via Gallery Kanban333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-100643SiYuan before v3.8.4 Stored XSS via Attribute View textarea333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-100673Grav Data Manager before 1.4.5 Stored XSS via item-detail view333140 , 333141 , 340095 , 340147 , 340148 , 342259 , 346755
CVE-2026-100858heym before 0.0.109 Server-Side Request Forgery via Workflow Nodes337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-100849AzuraCast before 0.23.8 SSRF Filter Bypass via Hostname and Private IPs337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-100859Heym before 0.0.106 Credential Exfiltration via URL Override337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-100601ClawHub SSRF via Unchecked DNS Resolution in Profile Image337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-100696Adminer before 6.0.2 Unauthenticated SSRF via Elasticsearch Driver337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2025-47828H5P-Nodejs-library Security Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 346755
CVE-2026-100681Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-100314mathurvishal CloudClassroom-PHP-Project updatedetailsfromstudent.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-100315mathurvishal CloudClassroom-PHP-Project mydetailsfaculty.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-100739mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-100697Adminer 6.0.0 Server-Side Request Forgery via ClickHouse driver337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-100861heym before 0.0.105 SSRF via credential-controlled base URLs337109 , 337110 , 344360 , 398021 , 398022
CVE-2023-54358WordPress adivaha Travel Plugin 2.3 Reflected XSS via isMobile333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-54361Joomla iProperty Real Estate 4.1.1 Reflected XSS via filter_keyword333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-54362Joomla VirtueMart Shopping-Cart 4.0.12 Reflected XSS via keyword333140 , 333141 , 340087 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-100630AVideo Stored XSS via HTML Entity Bypass in trailer1 Field333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-100850AzuraCast before 0.23.8 SSRF and Local File Read via Remote Playlist337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-100312mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-100313mathurvishal CloudClassroom-PHP-Project updatequery.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-84069WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php340007 , 344360 , 347009 , 390709
CVE-2026-96896Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deletion via wpmr_ajax_request340014 , 340023 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 360029 , 390904