Md Minaruzzaman Shovon

Building fast, thoughtful web products.

I'm Md Minaruzzaman Shovon, a full-stack developer focused on Next.js, TypeScript, modern UI systems, and AI-powered product experiences, with a background in water resources engineering and GIS.

I care about interfaces that feel clear, quick, and quietly capable, especially when the product has real-world data, mapping, or technical depth behind it.

Based in Chattogram, building for the web.

Recent work spans developer-focused interfaces, portfolio systems, interactive maps, and practical software for engineering-heavy use cases.

Featured Dataset & GEE Asset162 BWDB PoldersWGS84 EPSG:4326

Bangladesh Coastal Polders GIS & GEE Dataset Hub

Open-access spatial vector dataset of 162 coastal polders compiled, standardized, and published to Google Earth Engine by Md Minaruzzaman Shovon. Includes GEE sample code and Shapefile download.

Explore Dataset

Work Experience

TodvobChief Technology Officer (CTO), Jan 2026-Present
BlendinWeb Developer, 2025-Present
Logifu PTY LTDSenior Software Developer, 2025-2026

Security Advisories & Disclosures

Responsible vulnerability disclosures, CVE advisories, and official vendor changelog credits.

CVE-2026-15049 — Depicter Authenticated Arbitrary File Upload

Jul 2026

Discovered and reported CVE-2026-15049, a high-severity (CVSS 7.2) Arbitrary File Upload vulnerability in Depicter < 4.8.0. Inadequate archive validation during ZIP import enables Editor-level users to upload executable PHP files and achieve RCE. Patched in version 4.8.0.

WPScan / CVESecurity Research

CVE-2026-10749 — Post Duplicator PHP Object Injection

Jun 2026

Discovered and reported CVE-2026-10749, a high-severity (CVSS 7.2) PHP Object Injection vulnerability in Post Duplicator ≤ 3.0.14. Authenticated Contributors can inject malicious serialized objects via the customMetaData parameter, enabling remote code execution when a gadget chain is present. Patched in version 3.0.15.

WPScan / CVESecurity Research

CVE-2026-84021 — Bold Page Builder Stored Cross-Site Scripting (XSS)

Aug 2026

Discovered and reported CVE-2026-84021, a medium-severity (CVSS 6.8) Stored XSS vulnerability in Bold Page Builder < 5.9.8. Insufficient URL validation in shortcode attributes enables Contributor-level attackers to inject malicious script URIs. Patched in version 5.9.8.

WPScan / CVESecurity Research

CVE-2026-85678 — AI Builder Stored Cross-Site Scripting (XSS)

Sep 2026

Discovered and reported CVE-2026-85678, a medium-severity (CVSS 6.4) Stored XSS vulnerability in AI Builder < 2.7.8. Missing sanitization of custom JavaScript saved against posts allows Contributor-level users to inject arbitrary scripts inside inline script tags. Patched in version 2.7.8.

Wordfence / CVESecurity Research

CVE-2026-57661 — WPComplete Broken Access Control

Jun 2026

Discovered and reported CVE-2026-57661, a medium-severity (CVSS 5.4) Broken Access Control vulnerability in WPComplete ≤ 2.9.5.5. Missing authorization and nonce validation allows Subscriber-level users to perform privileged actions. Patched in version 2.9.5.6.

Patchstack / CVESecurity Research

CVE-2026-15048 — GeekyBot Unauthenticated Sensitive Information Exposure

Jul 2026

Discovered and reported CVE-2026-15048, a medium-severity (CVSS 5.3) Information Exposure vulnerability in GeekyBot < 1.2.8. Missing authorization checks allow unauthenticated attackers to retrieve chat-history session metadata, user IDs, and WordPress usernames. Patched in version 1.2.8.

WPScan / CVESecurity Research

CVE-2026-14822 — Event Tickets Unauthenticated PayPal Order Status Manipulation

Jul 2026

Discovered and reported CVE-2026-14822, a medium-severity (CVSS 5.3) Broken Access Control vulnerability in Event Tickets < 5.29.0.1. Missing authorization on a REST endpoint allows unauthenticated users to manipulate PayPal ticket order statuses. Patched in version 5.29.0.1.

WPScan / CVESecurity Research

CVE-2026-14322 — Timetics Unauthenticated Booking Auto-Approval

Jul 2026

Discovered and reported CVE-2026-14322, a medium-severity (CVSS 5.3) Broken Access Control vulnerability in Timetics < 1.0.57. Unauthenticated users can create fully-approved bookings for priced appointments without making any payment by manipulating payment_method. Patched in version 1.0.57.

WPScan / CVESecurity Research

CVE-2026-15151 — Five Star Restaurant Reservations Missing Authorization

Jul 2026

Discovered and reported CVE-2026-15151, a low-severity (CVSS 3.8) Missing Authorization vulnerability in Five Star Restaurant Reservations < 2.7.23. A missing capability check on the rtb_reset_notifications AJAX action lets Booking Manager users reset the site's notification rules. Patched in version 2.7.23.

WPScan / CVESecurity Research

CVE-2026-14821 — Quiz and Survey Master Missing Authorization

May 2026

Discovered and reported CVE-2026-14821, a low-severity (CVSS 2.7) Missing Authorization vulnerability in Quiz and Survey Master (QSM) < 11.1.5. Authenticated Contributors can delete arbitrary output templates due to missing capability checks. Patched in version 11.1.5.

WPScan / CVESecurity Research

MapPress Maps 2.97.2 Security Assistance

2026

Discovered and reported security vulnerabilities in MapPress Maps for WordPress. Received formal author appreciation and changelog recognition in version 2.97.2 ('Thanks to https://shovon.bd for security assistance in 2.97').

WordPress.orgSecurity Research

WP Store Locator 2.3.1 Security Fix

2026

Discovered and reported a high-severity Stored XSS vulnerability (CVSS 8.1) in WP Store Locator (<= 2.3.0). Coordinated a responsible disclosure resulting in a critical patch in version 2.3.1 and formal recognition in the changelog.

WordPress.orgSecurity Research

Skills

Technologies and tools I use to design, build, and ship products.

Frontend

  • Next.js
  • React
  • Expo (React Native)
  • TypeScript
  • Tailwind CSS

Backend

  • Node.js
  • Express.js
  • REST APIs
  • Authentication Systems

Database

  • MongoDB
  • Mongoose
  • Firebase

Certifications

CISSP by InfoSecInfoSEC, Jun 2025
Cybersecurity Attack and Defense FundamentalsEC-Council, Jun 2025
Microsoft Python DevelopmentMicrosoft, Jun 2025
Google Cybersecurity ProfessionalGoogle, Jun 2025
GIS & Its ApplicationEnhancing Digital Government & Economy Project, Apr 2025

Achievements

Ranked 11th - NextGen Hackathon

International Islamic University Chittagong

2025
Finalist - BCS ICT FEST 2025 (Top 21 of 150+ Teams)

Bangladesh Computer Society

2025
Ranked 246th out of 760 Participants - KnightCTF 2025

Organized by Knight Squad

2025
2nd Runner-Up - IEEE CS Hackathon

IEEE Computer Society, Bangladesh University of Engineering and Technology

2024
Local Qualifier - NASA Space Apps Challenge 2024

Earth Science Division, Science Mission Directorate, NASA

2024
Ranked 26th out of 106 Teams - SMP CTF 2024

Organized by SMP Cyber Security

2024
1st Place - AutoCAD Design Competition

Department of Water Resources Engineering, Chittagong University of Engineering and Technology

2023

Volunteer Experience

WRROJoint Research Secretary, 2025-Present
NogorfulICT Director, 2024-Present
OngkoFounder and President, 2019-2020

Education

Chittagong University of Engineering and Technology (CUET)Undergraduate, Water Resources Engineering
Chittagong CollegeCollege
Chattogram Cantonment Public CollegeSchool

Connect

I'm always open to discussing product, engineering, and collaborative opportunities.