Md Minaruzzaman Shovon
Building fast, thoughtful web products.
I'm Md Minaruzzaman Shovon, a full-stack developer focused on Next.js, TypeScript, modern UI systems, and AI-powered product experiences, with a background in water resources engineering and GIS.
I care about interfaces that feel clear, quick, and quietly capable, especially when the product has real-world data, mapping, or technical depth behind it.
Based in Chattogram, building for the web.
Recent work spans developer-focused interfaces, portfolio systems, interactive maps, and practical software for engineering-heavy use cases.
Bangladesh Coastal Polders GIS & GEE Dataset Hub
Open-access spatial vector dataset of 162 coastal polders compiled, standardized, and published to Google Earth Engine by Md Minaruzzaman Shovon. Includes GEE sample code and Shapefile download.
Work Experience
Security Advisories & Disclosures
Responsible vulnerability disclosures, CVE advisories, and official vendor changelog credits.
CVE-2026-15049 — Depicter Authenticated Arbitrary File Upload
Jul 2026Discovered and reported CVE-2026-15049, a high-severity (CVSS 7.2) Arbitrary File Upload vulnerability in Depicter < 4.8.0. Inadequate archive validation during ZIP import enables Editor-level users to upload executable PHP files and achieve RCE. Patched in version 4.8.0.
CVE-2026-10749 — Post Duplicator PHP Object Injection
Jun 2026Discovered and reported CVE-2026-10749, a high-severity (CVSS 7.2) PHP Object Injection vulnerability in Post Duplicator ≤ 3.0.14. Authenticated Contributors can inject malicious serialized objects via the customMetaData parameter, enabling remote code execution when a gadget chain is present. Patched in version 3.0.15.
CVE-2026-84021 — Bold Page Builder Stored Cross-Site Scripting (XSS)
Aug 2026Discovered and reported CVE-2026-84021, a medium-severity (CVSS 6.8) Stored XSS vulnerability in Bold Page Builder < 5.9.8. Insufficient URL validation in shortcode attributes enables Contributor-level attackers to inject malicious script URIs. Patched in version 5.9.8.
CVE-2026-85678 — AI Builder Stored Cross-Site Scripting (XSS)
Sep 2026Discovered and reported CVE-2026-85678, a medium-severity (CVSS 6.4) Stored XSS vulnerability in AI Builder < 2.7.8. Missing sanitization of custom JavaScript saved against posts allows Contributor-level users to inject arbitrary scripts inside inline script tags. Patched in version 2.7.8.
CVE-2026-57661 — WPComplete Broken Access Control
Jun 2026Discovered and reported CVE-2026-57661, a medium-severity (CVSS 5.4) Broken Access Control vulnerability in WPComplete ≤ 2.9.5.5. Missing authorization and nonce validation allows Subscriber-level users to perform privileged actions. Patched in version 2.9.5.6.
CVE-2026-15048 — GeekyBot Unauthenticated Sensitive Information Exposure
Jul 2026Discovered and reported CVE-2026-15048, a medium-severity (CVSS 5.3) Information Exposure vulnerability in GeekyBot < 1.2.8. Missing authorization checks allow unauthenticated attackers to retrieve chat-history session metadata, user IDs, and WordPress usernames. Patched in version 1.2.8.
CVE-2026-14822 — Event Tickets Unauthenticated PayPal Order Status Manipulation
Jul 2026Discovered and reported CVE-2026-14822, a medium-severity (CVSS 5.3) Broken Access Control vulnerability in Event Tickets < 5.29.0.1. Missing authorization on a REST endpoint allows unauthenticated users to manipulate PayPal ticket order statuses. Patched in version 5.29.0.1.
CVE-2026-14322 — Timetics Unauthenticated Booking Auto-Approval
Jul 2026Discovered and reported CVE-2026-14322, a medium-severity (CVSS 5.3) Broken Access Control vulnerability in Timetics < 1.0.57. Unauthenticated users can create fully-approved bookings for priced appointments without making any payment by manipulating payment_method. Patched in version 1.0.57.
CVE-2026-15151 — Five Star Restaurant Reservations Missing Authorization
Jul 2026Discovered and reported CVE-2026-15151, a low-severity (CVSS 3.8) Missing Authorization vulnerability in Five Star Restaurant Reservations < 2.7.23. A missing capability check on the rtb_reset_notifications AJAX action lets Booking Manager users reset the site's notification rules. Patched in version 2.7.23.
CVE-2026-14821 — Quiz and Survey Master Missing Authorization
May 2026Discovered and reported CVE-2026-14821, a low-severity (CVSS 2.7) Missing Authorization vulnerability in Quiz and Survey Master (QSM) < 11.1.5. Authenticated Contributors can delete arbitrary output templates due to missing capability checks. Patched in version 11.1.5.
MapPress Maps 2.97.2 Security Assistance
2026Discovered and reported security vulnerabilities in MapPress Maps for WordPress. Received formal author appreciation and changelog recognition in version 2.97.2 ('Thanks to https://shovon.bd for security assistance in 2.97').
WP Store Locator 2.3.1 Security Fix
2026Discovered and reported a high-severity Stored XSS vulnerability (CVSS 8.1) in WP Store Locator (<= 2.3.0). Coordinated a responsible disclosure resulting in a critical patch in version 2.3.1 and formal recognition in the changelog.
Featured In
Press coverage and external mentions of work I've contributed to.
Skills
Technologies and tools I use to design, build, and ship products.
Frontend
- Next.js
- React
- Expo (React Native)
- TypeScript
- Tailwind CSS
Backend
- Node.js
- Express.js
- REST APIs
- Authentication Systems
Database
- MongoDB
- Mongoose
- Firebase
Certifications
Achievements
International Islamic University Chittagong
Bangladesh Computer Society
Organized by Knight Squad
IEEE Computer Society, Bangladesh University of Engineering and Technology
Earth Science Division, Science Mission Directorate, NASA
Organized by SMP Cyber Security
Department of Water Resources Engineering, Chittagong University of Engineering and Technology
Volunteer Experience
Education
Gallery
A visual journey through my interests in engineering, development, and the environment.
Connect
I'm always open to discussing product, engineering, and collaborative opportunities.