Luciano Hanna

Cybersecurity Researcher

About Me

Luciano Hanna

Hello! I am Luciano Hanna, a Cybersecurity Researcher. I hold a Bachelor's degree and am currently a Master's student in Computer Science at the Fluminense Federal University (UFF).

With 4 years of prior experience as a Full-stack developer, I possess a deep architectural vision. This technical background allows me to perform advanced code audits (Whitebox) and accurately understand complex business logics. In my practical journey, I have assisted several organizations in identifying vulnerabilities — including names like ABB and Daimler Truck — and I have 6 published CVEs.

In the academic community, I contribute with published papers in prestigious national (SBSeg) and international (IEEE) symposiums. My research operates at the intersection of cybersecurity with areas such as computer networks, Internet of Things (IoT), and the application of Machine Learning for threat detection. Currently, my master's focus is on the study of vehicular networks and the emerging field of Automotive Cybersecurity. In my free time, my hobby is participating in CTFs (Capture The Flag) for continuous practice, and I maintain a blog where I share write-ups and technical analyses.

Discovered Vulnerabilities (CVEs)

CVSS 9.1 CWE-94
Improper Control of Generation of Code ('Code Injection') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Remote Code Inclusion. CNA: Patchstack OÜ
CVSS 6.4 CWE-79
Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in the Advanced iFrame plugin up to version 2024.5. CNA: Wordfence
CVSS 7.3 CWE-94
Arbitrary shortcode execution in the Simply Schedule Appointments Booking plugin up to version 1.6.8.5. CNA: Wordfence [Write-up]
CVSS 5.3 CWE-200
Sensitive Information Exposure in the Melhor Envio plugin up to version 2.15.9 via the 'run' function using a hardcoded hash. CNA: Wordfence
CVSS 6.1 CWE-79
Reflected Cross-Site Scripting via the rf parameter in the Accept Donations with PayPal & Stripe plugin up to version 1.4.4. CNA: Wordfence [Write-up]
CVSS 6.1 CWE-79
Reflected Cross-Site Scripting via the accent_color and background parameters in the Simply Schedule Appointments Booking plugin up to version 1.6.8.3. CNA: Wordfence [Write-up]

Capture The Flag (CTF)

BSidesRJ CTF 🥈 2nd Place 2026

Participation in the Capture The Flag (CTF) competition by BSidesRJ 2026, focused on practical offensive security challenges and vulnerability exploitation.

Trophy for winning 2nd place