HTML entities inside JavaScript URL
Shows which HTML entities are allowed inside the JavaScript protocol
Created by: hackvertor
Created on: Tuesday, June 25, 2024 at 11:56:40 AM
Updated on: Wednesday, May 28, 2025 at 5:08:10 PM
Detecting browser...
Category: Entity Parsing
Vector visibility: Public
Vector type: JS
Vector charset: UTF-8
Vector data 1: html_entities
Code used before fuzz:
const div = document.createElement('div');Template used:
div.innerHTML='<a href="java$[data1]script:">test</a>';0x0D
div.querySelector('a').protocol === 'javascript:' && log('$[data1]')Sample payloads
div.innerHTML='<a href="java
script:">test</a>';0x0D
div.querySelector('a').protocol === 'javascript:' && alert('
')div.innerHTML='<a href="java	script:">test</a>';0x0D
div.querySelector('a').protocol === 'javascript:' && alert('	')Fuzz results
Chrome 144.0.0.0 desktop Windows NT 10.0
Updated
Wed Jan 28 2026
Found 2 results
Loading...
Chrome 126.0.0.0 desktop macOS 10.15.7older version
Updated
Tue Jun 25 2024
Found 2 results
Loading...
Firefox 147.0 desktop Windows NT 10.0
Updated
Thu Jan 29 2026
Found 2 results
Loading...
Firefox 127.0 desktop macOS 10.15older version
Updated
Tue Jun 25 2024
Found 2 results
Loading...
Microsoft Edge 144.0.0.0 desktop Windows NT 10.0
Updated
Fri Jan 30 2026
Found 2 results
Loading...
Safari 17.4 desktop macOS 10.15.7
Updated
Tue Jun 25 2024
Found 2 results
Loading...