| Entities allowed as JS variables | hackvertor | 7/2/2024 | XSS | 1 |
| Entities still parsed in uppercase | hackvertor | 7/2/2024 | JS | 0 |
| Entities allowed between function call and number | hackvertor | 7/2/2024 | XSS | 0 |
| Entities allowed inside function name | hackvertor | 7/2/2024 | XSS | 0 |
| Entities allowed before function calls | hackvertor | 7/2/2024 | XSS | 0 |
| Characters allowed after malformed entities | hackvertor | 7/1/2024 | XSS | 0 |
| Entities allowed between function calls | hackvertor | 6/29/2024 | XSS | 0 |
| HTML entities that create ASCII characters inside a JavaScript URL | hackvertor | 6/25/2024 | JS | 3 |
2 2 | HTML entities before JavaScript URL | hackvertor | 6/25/2024 | JS | 0 |
| HTML entities inside JavaScript URL before colon | hackvertor | 6/25/2024 | JS | 0 |
| HTML entities inside JavaScript URL | hackvertor | 6/25/2024 | JS | 0 |
| Characters that act as array literals | hackvertor | 6/24/2024 | JS | 0 |
| Characters that act as parentheses | hackvertor | 6/24/2024 | JS | 0 |
31 | Characters allowed after greater than in events | hackvertor | 6/21/2024 | XSS | 0 |
| Characters that act as new lines in multi line strings | hackvertor | 6/20/2024 | JS | 1 |
| Characters ignored after backslash with multiline string | hackvertor | 6/18/2024 | JS | 0 |
| Characters ignored in strings when doing a non strict comparison | hackvertor | 6/18/2024 | JS | 0 |
| Properties that are accessible on location | hackvertor | 6/7/2024 | JS | 0 |
| Properties are accessible in a sandboxed iframe | hackvertor | 6/7/2024 | JS | 0 |
| Properties that leak the parent URL even when sandboxed | hackvertor | 6/6/2024 | JS | 0 |