- Cybersecurity researcher focused on vulnerability discovery, exploitation, and secure development.
- Credited with 20+ CVEs, including RCE and File Upload Bypass vulnerabilities across open-source platforms.
- Ranked Top 10 consecutively for 12+ weeks in HackTheBox Pakistan with expertise in web, privilege escalation, and active directory machines.
- Strong foundation in Python-based security tooling, exploit development, and Linux.
- Author of technical writeups, educational resources, and open-source security research.
- Publishing technical writeups on CVE discoveries
- Security research in web applications and open-source platforms
- Seventh semester at Muhammad Ali Jinnah University
| Platform | CVE IDs | Type |
|---|---|---|
| Mentingo LMS | CVE-2025-10388, CVE-2025-10741, CVE-2025-10755 | XSS, File Upload, Restriction Bypass |
| Academico | CVE-2025-10763 | File Upload → RCE |
| Vvveb CMS (with Hamed Kohi) | CVE-2025-11026, CVE-2025-11027, CVE-2025-11028, CVE-2025-11029 | Info Disclosure, CSRF, File Upload to RCE |
| Frappe LMS (with Hamed Kohi) | CVE-2025-11280, CVE-2025-11281, CVE-2025-11282, CVE-2025-11283 | Privilege Escalation & Access Control |
| learnhouse | CVE-2025-12268, CVE-2025-12269, CVE-2025-12270, CVE-2025-12276 | Client-Side Enforcement of Server-Side Security, Unrestricted Upload, Insecure Direct Object Reference, Info Disclosure |
| OpenCart | CVE-2025-15116 | Race Condition/TOCTOU |
| Grav | GHSA-w8cg-7jcj-4vv2/CVE-2026-42611 | XSS |
| Grafana | CVE-2026-21722, CVE-2026-33375, CVE-2026-33381, CVE-2026-28374 | BOPLA, DoS |
| GhostCMS | CVE-2026-25552 | Rate-Limit Bypass via Header Injection |
- SecureSys – Flask-based Vulnerability Assessment Platform with XSS and SQLi labs.
- Yarghamal – C-based File Encryption & Monitoring system using secure client-server key exchange.
- Personal Blog – Deep-dive articles on exploitation, and research methodology.
- 1st Place, ACM MAJU Competitive Programming Contest (2024)
- Top 5 Finalist, Ignite National Cybersecurity Hackathon (2024)
- 45+ HTB machines and 66+ picoCTF challenges solved
Penetration Testing · Vulnerability Assessment · Exploit Development
Python · C++ · Bash · PowerShell · Burp Suite · Metasploit · SQL
khanmarshai.github.io
github.com/KhanMarshaI
iamtaha05@gmail.com
linkedin
