Md Minaruzzaman Shovon
Building fast, thoughtful web products.
I'm Md Minaruzzaman Shovon, a full-stack developer focused on Next.js, TypeScript, modern UI systems, and AI-powered product experiences, with a background in water resources engineering and GIS.
I care about interfaces that feel clear, quick, and quietly capable, especially when the product has real-world data, mapping, or technical depth behind it.
Based in Chattogram, building for the web.
Recent work spans developer-focused interfaces, portfolio systems, interactive maps, and practical software for engineering-heavy use cases.
Work Experience
Security Advisories & Disclosures
Responsible vulnerability disclosures, CVE advisories, and official vendor changelog credits.
CVE-2026-15048 — GeekyBot Unauthenticated Sensitive Information Exposure
Jul 2026Discovered and reported CVE-2026-15048, a medium-severity (CVSS 5.3) Information Exposure vulnerability in GeekyBot < 1.2.8. Missing authorization checks allow unauthenticated attackers to retrieve chat-history session metadata, user IDs, and WordPress usernames. Patched in version 1.2.8.
CVE-2026-14322 — Timetics Unauthenticated Booking Auto-Approval
Jul 2026Discovered and reported CVE-2026-14322, a medium-severity (CVSS 5.3) Broken Access Control vulnerability in Timetics < 1.0.57. Unauthenticated users can create fully-approved bookings for priced appointments without making any payment by manipulating payment_method. Patched in version 1.0.57.
CVE-2026-10749 — Post Duplicator PHP Object Injection
Jun 2026Discovered and reported CVE-2026-10749, a high-severity (CVSS 7.2) PHP Object Injection vulnerability in Post Duplicator ≤ 3.0.14. Authenticated Contributors can inject malicious serialized objects via the customMetaData parameter, enabling remote code execution when a gadget chain is present. Patched in version 3.0.15.
CVE-2026-57661 — WPComplete Broken Access Control
Jun 2026Discovered and reported CVE-2026-57661, a medium-severity (CVSS 5.4) Broken Access Control vulnerability in WPComplete ≤ 2.9.5.5. Missing authorization and nonce validation allows Subscriber-level users to perform privileged actions. Patched in version 2.9.5.6.
CVE-2026-14821 — Quiz and Survey Master Missing Authorization
May 2026Discovered and reported CVE-2026-14821, a low-severity (CVSS 2.7) Missing Authorization vulnerability in Quiz and Survey Master (QSM) < 11.1.5. Authenticated Contributors can delete arbitrary output templates due to missing capability checks. Patched in version 11.1.5.
MapPress Maps 2.97.2 Security Assistance
2026Discovered and reported security vulnerabilities in MapPress Maps for WordPress. Received formal author appreciation and changelog recognition in version 2.97.2 ('Thanks to https://shovon.bd for security assistance in 2.97').
WP Store Locator 2.3.1 Security Fix
2026Discovered and reported a high-severity Stored XSS vulnerability (CVSS 8.1) in WP Store Locator (<= 2.3.0). Coordinated a responsible disclosure resulting in a critical patch in version 2.3.1 and formal recognition in the changelog.
Featured In
Press coverage and external mentions of work I've contributed to.
Skills
Technologies and tools I use to design, build, and ship products.
Frontend
- Next.js
- React
- Expo (React Native)
- TypeScript
- Tailwind CSS
Backend
- Node.js
- Express.js
- REST APIs
- Authentication Systems
Database
- MongoDB
- Mongoose
- Firebase
Certifications
Achievements
International Islamic University Chittagong
Bangladesh Computer Society
Organized by Knight Squad
IEEE Computer Society, Bangladesh University of Engineering and Technology
Earth Science Division, Science Mission Directorate, NASA
Organized by SMP Cyber Security
Department of Water Resources Engineering, Chittagong University of Engineering and Technology
Volunteer Experience
Education
Gallery
A visual journey through my interests in engineering, development, and the environment.
Connect
I'm always open to discussing product, engineering, and collaborative opportunities.