| Impossible lab frameset | renniepak | 11/27/2024 | HTML | 0 |
| Find WAF bypass for eval context | elieehel | 11/22/2024 | JS | 0 |
| Characters transformed when using lowercase | hackvertor | 11/18/2024 | JS | 0 |
| Characters transformed when using uppercase | hackvertor | 11/18/2024 | JS | 0 |
2124 | Chars in href that will not default to full URL | joaxcar | 11/16/2024 | XSS | 0 |
29 | Non-standard characters that break JSON.parse() | DreyAnd | 11/15/2024 | JS | 1 |
4 | HTML elements that inherit properties which return the full URL | 0x999-x | 11/14/2024 | XSS | 0 |
17 | URL scheme separator alternatives | simoneonofri | 11/14/2024 | JS | 0 |
1 | Characters that can be between < and script> | m10x | 11/12/2024 | HTML | 0 |
| Characters that cause the backslash to be consumed with GBK charset | hackvertor | 11/7/2024 | XSS | 0 |
| Characters that can precede the javascript protocol copy2 | PinkDraconian | 11/7/2024 | XSS | 0 |
3 | Characters allowed javascript and colon copy2 copy2 | PinkDraconian | 11/7/2024 | JS | 0 |
| Characters that close or encapsulate HTML attribute values | ola456 | 11/5/2024 | XSS | 1 |
9 | XSS vectors that consume tag | Y4tacker | 11/5/2024 | XSS | 2 |
20 | HTML tags and attributes that can be used to access the URL | 0x999-x | 11/4/2024 | XSS | 1 |
2 | HTML tags that can clobber the credentials part of the URL | 0x999-x | 11/4/2024 | XSS | 1 |
| Characters that cause the backslash to be consumed with a big5 charset | hackvertor | 11/1/2024 | XSS | 0 |
| Differences between escape vs encodeURIComponent | hackvertor | 10/15/2024 | JS | 0 |
1 1 | < removal bypass | Device1306 | 10/9/2024 | HTML | 0 |
| Entities in-between square brackets that close cdata | hackvertor | 10/8/2024 | XSS | 1 |