Security Researcher

Onurcan Genç

Offensive security researcher and AI red-teamer. I find vulnerabilities in web applications and language models, then publish the findings so defenders can act on them.

Selected Findings

NocoBase VM Sandbox Escape

CVSS 10.0

Full server compromise through the formula/scripting engine.

Mautic SSTI-to-RCE Chain

CVSS 9.9

Server-side template injection escalating to remote code execution.

Ghost CMS SSRF

Critical

Server-side request forgery in the Ghost publishing platform.

Moodle & Decap CMS

Multiple CVEs

XSS, IDOR, and prompt injection across LMS and headless CMS.