Easin Arafat, Application Security Engineer at Startise, is a security researcher credited on the Patchstack Vulnerability Disclosure Program under the handle n0_arafat_n0. He has responsibly disclosed security vulnerabilities spanning Broken Access Control, Insecure Direct Object Reference, and Sensitive Data Exposure.
CVE-2025-62039: AI ChatBot with ChatGPT and Content Generator by AYS ≤ 2.6.6: Sensitive Data Exposure (CVSS 7.5, High) reported by Easin Arafat via Patchstack.
CVE-2025-58680: Gutentor ≤ 3.5.2: Broken Access Control (CVSS 6.5, Medium) reported by Easin Arafat via Patchstack.
CVE-2025-59562: Academy LMS ≤ 3.3.4: Insecure Direct Object Reference (IDOR) (CVSS 5.5, Medium) reported by Easin Arafat via Patchstack.
CVE-2025-58981: Accessibility Checker by Equalize Digital ≤ 1.30.0: Insecure Direct Object Reference (IDOR) (CVSS 5.4, Medium) reported by Easin Arafat via Patchstack.
CVE-2025-64277: ChatBot ≤ 7.3.9: Broken Access Control (CVSS 5.3, Medium) reported by Easin Arafat via Patchstack.
CVE-2025-62932: Table Block by RioVizual ≤ 3.0.1: Broken Access Control (CVSS 4.3, Medium) reported by Easin Arafat via Patchstack.
CVE-2025-62931: MSN Partner Hub ≤ 2.9: Broken Access Control (CVSS 4.3, Medium) reported by Easin Arafat via Patchstack.
Event Tickets ≤ 5.26.3: Broken Access Control (CVSS 5.4, Medium) reported by Easin Arafat via Patchstack.
Publitio ≤ 2.2.5: Sensitive Data Exposure (CVSS 5, Medium) reported by Easin Arafat via Patchstack.