Shazzer logo

Characters allowed in between start of HTML tag name and event handler

Chrome logo 6
Firefox logo 6
Edge logo 6
Safari logo 6

Characters allowed in between start of HTML tag name and event handler

AyushXtha
Created byAyushXtha
Created Mar 4, 2026
Updated Mar 4, 2026

Tweet
Detecting browser...
CategoryHTML Parsing
VisibilityPublic
TypeXSS
CharsetUTF-8
Template used:
<a$[chr]id="test">
Code used after fuzz:
document.getElementById('test') && log(i)

Sample payloads

<a0x09id="test">
<a
id="test">
<a0x0Cid="test">
<a0x0Did="test">
<a id="test">
<a/id="test">

Fuzz results

Chrome logo
Chrome 148.0.0.0 desktop Windows NT 10.0
Updated15 Mar 2026
Found 6 results
Loading...
Chrome logo
Chrome 146.0.0.0 desktop macOS 10.15.7older version
Updated9 Mar 2026
Found 6 results
Loading...
Chrome logo
Chrome 145.0.0.0 desktop Linuxolder version
Updated9 Mar 2026
Found 6 results
Loading...
Firefox logo
Firefox 150.0 desktop macOS 10.15
Updated14 Mar 2026
Found 6 results
Loading...
Firefox logo
Firefox 148.0 desktop Linux Unknownolder version
Updated5 Mar 2026
Found 6 results
Loading...
Edge logo
Microsoft Edge 146.0.0.0 desktop Windows NT 10.0
Updated21 Mar 2026
Found 6 results
Loading...
Safari logo
Safari 26.0.1 mobile iOS 18.7
Updated4 Mar 2026
Found 6 results
Loading...