Riyadh, Kingdom of Saudi Arabia

Penetration Tester &
Bug Bounty Hunter

I find and responsibly disclose real-world vulnerabilities in web applications, the CVEs I publish stand on the public record, and my reports are credited by the vendors who ship the fixes.

  • 0CVEs published
  • 0Reports filed
  • 0BugBounty.sa points
  • 0Competition podiums

01 · About

Security research with a public paper trail.

I'm Abdulaziz Alasaiqah, a 16-year-old penetration tester and bug bounty hunter based in Riyadh. My work centres on web application security, hunting for the logic flaws, injection points and access-control gaps that survive automated scanning, and reporting them through responsible disclosure.

I'm an active researcher on BugBounty.sa, Saudi Arabia's national platform, where I've filed 132 reports for 1,500 points. Two of my findings are published CVEs, one of them patched by Mozilla in Firefox 150 and ESR 140.10, and I've placed at three regional security competitions including Black Hat MEA 2025.

eCPPT certificate awarded to Abdulaziz Alasaiqah by INE Security, 17 May 2025

eCPPTv3

Issued 17 May 2025 · ID 143537278

Verify
eJPT certificate awarded to Abdulaziz Alasaiqah by INE Security, 18 December 2024

eJPTv2

Issued 18 December 2024 · ID 126900387

Verify

02 · Track Record

Findings, credits and podiums.

Everything below is verifiable, published CVEs, platform credits and competition results.

  1. CVE

    CVE-2026-6765 · Firefox Form Autofill

    Reported to Mozilla and patched in Firefox 150 and ESR 140.10. Awarded a 3,750 SAR bounty.

    Mozilla · Patched
  2. CVE

    CVE-2026-39154 · Stored XSS in CometChat

    Discovered and responsibly disclosed; officially credited by the platform.

    CometChat · Fixed
  3. 3rd

    Black Hat MEA 2025 · Bug Bounty Junior

    Third place at one of the region's largest cybersecurity gatherings.

    Riyadh · 2025
  4. 2nd

    Defenseathon (#GADD), Project Sate'

    Second place in the Defenseathon challenge.

    Challenge
  5. 3rd

    BugBounty Joiner Competition

    Third place finish.

    Competition
  6. SA

    BugBounty.sa, National Platform

    Active researcher, 132 reports filed across 1,500 points.

    1,500 pts

On the podium, click to enlarge.

Abdulaziz Alasaiqah receiving the third-place prize at the Black Hat MEA 2025 Bug Bounty Junior competition
Black Hat MEA 2025 Bug Bounty Junior · 3rd place · SAR 5,000
Abdulaziz Alasaiqah receiving the second-place prize at the Defensethon challenge
Defensethon (#GADD) Project Sate' · 2nd place · SAR 15,000

03 · Expertise

What I actually do.

Offensive Security

Black-box and grey-box testing of web applications, from recon through to a written report a developer can act on.

  • Web App Pentesting
  • Bug Bounty
  • XSS
  • Injection
  • Logic Flaws
  • Access Control
  • Responsible Disclosure

Vulnerability Research

Chasing a finding all the way to a CVE, reproducing it, proving impact, and writing it up so the vendor can ship a fix.

  • CVE Research
  • Responsible Disclosure
  • Proof of Concept
  • Impact Analysis
  • Vendor Reporting

Tooling & Automation

Building the small tools the testing needs, scripting repetitive recon so the time goes into the interesting bugs.

  • Python
  • JavaScript
  • Burp Suite
  • Automation
  • Scripting
  • Recon
National emblem of the Kingdom of Saudi Arabia, two crossed swords and a palm tree

04 · The Kingdom

Serving the Kingdom's security.

A proud citizen of the Kingdom of Saudi Arabia, working to strengthen its digital defenses.

Custodian of the Two Holy Mosques King Salman bin Abdulaziz Al Saud
خادم الحرمين الشريفين
الملك سلمان بن عبدالعزيز آل سعود
Custodian of the Two Holy Mosques
King Salman bin Abdulaziz Al Saud
HRH Prince Khalid bin Salman bin Abdulaziz Al Saud, Minister of Defense
صاحب السمو الملكي الأمير
خالد بن سلمان بن عبدالعزيز آل سعود
HRH Prince Khalid bin Salman
Minister of Defense

05 · Contact

Let's talk security.

Open to penetration testing engagements, security research collaborations and full-time positions.

abdulazizalasaiqah@gmail.com