Shazzer logo

Tags that HTML encode it's contents

Chrome logo 2
Firefox logo 2
Edge logo 2
Safari logo 2

This enumerates through all HTML tags and checks if the span gets HTML encoded.

hackvertor
Created byhackvertor
Created Jul 16, 2024
Updated May 27, 2025

Tweet
Detecting browser...
CategoryHTML Parsing
VisibilityPublic
TypeXSS
CharsetUTF-8
$[data1] placeholderhtml
Template used:
<$[data1] id=x><span></span></$[data1]>
Code used after fuzz:
x.innerHTML.includes('&lt;')  && log('$[data1]')

Sample payloads

<textarea id=x><span></span></textarea>
<title id=x><span></span></title>

Fuzz results

Chrome logo
Chrome 145.0.0.0 desktop Windows NT 10.0
Updated17 Feb 2026
Found 2 results
Loading...
Chrome logo
Chrome 144.0.0.0 desktop macOS 10.15.7older version
Updated17 Feb 2026
Found 2 results
Loading...
Firefox logo
Firefox 147.0 desktop Linux
Updated1 Feb 2026
Found 2 results
Loading...
Firefox logo
Firefox 128.0 desktop macOS 10.15older version
Updated16 Jul 2024
Found 2 results
Loading...
Edge logo
Microsoft Edge 145.0.0.0 desktop Windows NT 10.0
Updated18 Feb 2026
Found 2 results
Loading...
Safari logo
Safari 17.4 desktop macOS 10.15.7
Updated16 Jul 2024
Found 2 results
Loading...