| Characters prepended to URL host. check if difference between URL and a tag | InsertScript | 1/10/2025 | JS | 0 |
30 | Characters prepended to URL, which yield in the same host property | InsertScript | 1/10/2025 | JS | 0 |
31 | Characters appended at the end of TLD within URL, which yield in the same host property | InsertScript | 1/10/2025 | JS | 0 |
6 | Allowed characters right after tag name & before tag closure, no other characters in between | hansmach1ne | 1/9/2025 | XSS | 0 |
25 | Loose comparison, characters appended which still result in type coercion | hansmach1ne | 1/6/2025 | JS | 0 |
16 | Difference between browser-supported handlers and Shazzer 'all_browser_events' list | hansmach1ne | 1/5/2025 | JS | 0 |
20 | Difference between browser-supported handlers and Shazzer 'events' list | hansmach1ne | 1/5/2025 | JS | 0 |
275 | Characters appended at the end of TLD within URL, which yield in the same Origin | hansmach1ne | 1/5/2025 | JS | 2 |
127 | HTML TAGS Lists | Y4tacker | 1/3/2025 | XSS | 0 |
2 | Bytes that will scramble ISO-2022-JP | Cillian-Collins | 12/26/2024 | XSS | 1 |
2 | Bytes that will normalize ISO-2022-JP | Cillian-Collins | 12/26/2024 | XSS | 1 |
30 30 | Characters allowed after equals sign for event | YouGina | 12/17/2024 | XSS | 1 |
12 | Unicode characters that get normalized into path traversal characters | hackvertor | 12/12/2024 | JS | 2 |
| ISO-2022-JP ASCII escape sequence | hackvertor | 12/11/2024 | XSS | 1 |
| Impossible lab frameset | renniepak | 11/27/2024 | HTML | 0 |
| Find WAF bypass for eval context | elieehel | 11/22/2024 | JS | 0 |
| Characters transformed when using lowercase | hackvertor | 11/18/2024 | JS | 0 |
| Characters transformed when using uppercase | hackvertor | 11/18/2024 | JS | 0 |
2124 | Chars in href that will not default to full URL | joaxcar | 11/16/2024 | XSS | 0 |
29 | Non-standard characters that break JSON.parse() | DreyAnd | 11/15/2024 | JS | 1 |