5 5 | Tags that DO NOT support HTML comments | hackvertor | 1/26/2025 | XSS | 0 |
106 106 | Tags that support HTML comments | hackvertor | 1/26/2025 | XSS | 0 |
| Tags that get moved out of parent | hackvertor | 1/22/2025 | XSS | 0 |
| Tags that get reordered in the DOM | hackvertor | 1/21/2025 | XSS | 0 |
| Malformed HTML comments | hackvertor | 1/17/2025 | XSS | 0 |
| Characters allowed before the JavaScript protocol | hackvertor | 1/16/2025 | XSS | 0 |
| Entities allowed before slashes which result in an external URL | hackvertor | 1/16/2025 | XSS | 0 |
| Characters allowed before slashes which result in an external URL | hackvertor | 1/16/2025 | XSS | 1 |
| Characters allowed after slashes which result in an external URL | hackvertor | 1/16/2025 | XSS | 0 |
| Characters allowed after colon which result in an external URL | hackvertor | 1/16/2025 | XSS | 0 |
| Entities allowed between slashes using XSS type | hackvertor | 1/16/2025 | XSS | 0 |
| Characters allowed between slashes using XSS type | hackvertor | 1/16/2025 | XSS | 0 |
12 | Unicode characters that get normalized into path traversal characters | hackvertor | 12/12/2024 | JS | 2 |
| ISO-2022-JP ASCII escape sequence | hackvertor | 12/11/2024 | XSS | 1 |
| Characters transformed when using lowercase | hackvertor | 11/18/2024 | JS | 0 |
| Characters transformed when using uppercase | hackvertor | 11/18/2024 | JS | 0 |
| Characters that cause the backslash to be consumed with GBK charset | hackvertor | 11/7/2024 | XSS | 0 |
| Characters that cause the backslash to be consumed with a big5 charset | hackvertor | 11/1/2024 | XSS | 0 |
| Differences between escape vs encodeURIComponent | hackvertor | 10/15/2024 | JS | 1 |
| Entities in-between square brackets that close cdata | hackvertor | 10/8/2024 | XSS | 1 |