| Mutated XSS with img onerror | sqjor | 7/30/2024 | XSS | 0 |
| Entities that convert to less than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Entities that convert to greater than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| HTML tags that force HTML mode inside SVG | hackvertor | 8/2/2024 | XSS | 1 |
6 | Characters that can work as attribute seperator | Sudistark | 8/17/2024 | JS | 0 |
| Characters allowed before event in attribute name using setAttribute | hackvertor | 8/21/2024 | JS | 0 |
| Characters allowed in path traversal | joaxcar | 8/26/2024 | JS | 0 |
| Bypasses for __proto__ string match | vitorfhc | 8/29/2024 | JS | 0 |
1 | Bypass __proto__ string match defense | vitorfhc | 8/29/2024 | JS | 0 |
4 | URL domain dot alternatives | JorianWoltjer | 9/10/2024 | JS | 4 |
5 | Characters allowed between multiple HTML attributes | JorianWoltjer | 9/12/2024 | XSS | 2 |
4 | Entities allowed between two forward slashes | InsertScript | 9/19/2024 | XSS | 1 |
| Characters allowed in colon entity | InsertScript | 9/19/2024 | XSS | 0 |
2 | JIS X 0208 bytes that produce ASCII characters | JorianWoltjer | 9/22/2024 | JS | 1 |
| Characters urlencoded that get transformed when using the credentials part of the URL | hackvertor | 9/24/2024 | JS | 0 |
| Characters not urlencoded when using the shema part of the URL | d0ge | 9/24/2024 | JS | 0 |
| Characters unencoded characters supported in the hash | hackvertor | 9/24/2024 | JS | 1 |
| Chars allowed before domain | t0xodile | 9/24/2024 | XSS | 0 |
| Characters that cause an external URL before @ | hackvertor | 9/25/2024 | JS | 2 |
| Entities that cause an external URL before @ | hackvertor | 9/25/2024 | XSS | 4 |