Entities still parsed in uppercase
This vector transforms each entity into uppercase and checks if it is still rendered.
Created byhackvertor
Created Jul 2, 2024
Updated May 27, 2025
Detecting browser...
CategoryEntity Parsing
VisibilityPublic
TypeJS
CharsetUTF-8
$[data1] placeholderhtml_entities
Code used before fuzz:
const div = document.createElement('div');Template used:
let entity = '$[data1]'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '$[data1]') {0x0D
log(entity);0x0D
}Sample payloads
let entity = '&'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '&') {0x0D
alert(entity);0x0D
}let entity = '©'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '©') {0x0D
alert(entity);0x0D
}let entity = '©SR;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '©SR;') {0x0D
alert(entity);0x0D
}let entity = 'ⅅ'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== 'ⅅ') {0x0D
alert(entity);0x0D
}let entity = 'Ŋ'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== 'Ŋ') {0x0D
alert(entity);0x0D
}let entity = 'Ð'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== 'Ð') {0x0D
alert(entity);0x0D
}let entity = '>CC;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '>CC;') {0x0D
alert(entity);0x0D
}let entity = '>CIR;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '>CIR;') {0x0D
alert(entity);0x0D
}let entity = '>'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '>') {0x0D
alert(entity);0x0D
}let entity = '>DOT;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '>DOT;') {0x0D
alert(entity);0x0D
}let entity = '>LPAR;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '>LPAR;') {0x0D
alert(entity);0x0D
}let entity = '>QUEST;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '>QUEST;') {0x0D
alert(entity);0x0D
}let entity = '>RAPPROX;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '>RAPPROX;') {0x0D
alert(entity);0x0D
}let entity = '>RARR;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '>RARR;') {0x0D
alert(entity);0x0D
}let entity = '>RDOT;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '>RDOT;') {0x0D
alert(entity);0x0D
}let entity = '>REQLESS;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '>REQLESS;') {0x0D
alert(entity);0x0D
}let entity = '>REQQLESS;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '>REQQLESS;') {0x0D
alert(entity);0x0D
}let entity = '>RLESS;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '>RLESS;') {0x0D
alert(entity);0x0D
}let entity = '>RSIM;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '>RSIM;') {0x0D
alert(entity);0x0D
}let entity = '<CC;'.toUpperCase();0x0D
div.innerHTML= entity;0x0D
if(!div.innerText.includes(entity) && entity !== '<CC;') {0x0D
alert(entity);0x0D
}Fuzz results
Chrome 145.0.0.0 desktop Windows NT 10.0
Updated17 Feb 2026
Found 35 results
Loading...
Chrome 144.0.0.0 mobile Android 10older version
Updated31 Jan 2026
Found 35 results
Loading...
Chrome 144.0.0.0 desktop macOS 10.15.7older version
Updated17 Feb 2026
Found 35 results
Loading...
Firefox 147.0 desktop Linux
Updated1 Feb 2026
Found 35 results
Loading...
Firefox 143.0 desktop Windows NT 10.0older version
Updated25 Sept 2025
Found 35 results
Loading...
Firefox 127.0 desktop macOS 10.15older version
Updated2 Jul 2024
Found 35 results
Loading...
Microsoft Edge 144.0.0.0 desktop Windows NT 10.0
Updated31 Jan 2026
Found 35 results
Loading...
Safari 17.5 mobile iOS 17.5.1
Updated2 Jul 2024
Found 35 results
Loading...
Safari 17.4 desktop macOS 10.15.7older version
Updated2 Jul 2024
Found 35 results
Loading...