Shazzer logo

Entities that convert to greater than in a iframe srcdoc

Chrome logo 3
Firefox logo 3
Edge logo 3
Safari logo 3

This shows which entities convert to the greater than character inside a iframe srcdoc. Inspired by: https://x.com/therceman/status/1803666353892585642

hackvertor
Created byhackvertor
Created Aug 1, 2024
Updated May 27, 2025

Tweet
Detecting browser...
CategoryEntity Parsing
VisibilityPublic
TypeXSS
CharsetUTF-8
$[data1] placeholderhtml_entities
Template used:
<iframe srcdoc="$[data1]" id=x></iframe>
Code used after fuzz:
if(x.srcdoc.includes(">"))log('$[data1]')

Sample payloads

<iframe srcdoc="&gt;" id=x></iframe>
<iframe srcdoc="&GT;" id=x></iframe>
<iframe srcdoc="&nvgt;" id=x></iframe>

Fuzz results

Chrome logo
Chrome 144.0.0.0 desktop Windows NT 10.0
Updated31 Jan 2026
Found 3 results
Loading...
Chrome logo
Chrome 143.0.0.0 desktop macOS 10.15.7older version
Updated31 Jan 2026
Found 3 results
Loading...
Firefox logo
Firefox 147.0 desktop Linux
Updated1 Feb 2026
Found 3 results
Loading...
Firefox logo
Firefox 131.0 desktop macOS 10.15older version
Updated24 Oct 2024
Found 3 results
Loading...
Edge logo
Microsoft Edge 144.0.0.0 desktop Windows NT 10.0
Updated31 Jan 2026
Found 3 results
Loading...
Safari logo
Safari 17.5 mobile iOS 17.5.1
Updated1 Aug 2024
Found 3 results
Loading...