| Characters that are valid JS variables | hackvertor | 4/29/2024 | JS | 0 |
1 | Characters allowed instead of equal sign | c3l3si4n | 4/28/2024 | XSS | 0 |
| HTML elements that are self closing or different text content | hackvertor | 4/19/2024 | XSS | 2 |
| HTML elements that parse differently when rendered | hackvertor | 4/19/2024 | XSS | 1 |
1 1 | XSS vectors that execute automatically inside math | hackvertor | 4/17/2024 | XSS | 0 |
1 1 | XSS vectors that execute automatically inside svg | hackvertor | 4/17/2024 | XSS | 0 |
| XSS vectors that execute automatically | hackvertor | 4/17/2024 | XSS | 0 |
| Characters allowed between hostname and / but don't change the hostname | ThomasOrlita | 4/15/2024 | JS | 4 |
| Characters allowed after hostname but don't change the hostname | ThomasOrlita | 4/15/2024 | JS | 2 |
7 7 | Characters between element name and > | ThomasOrlita | 4/15/2024 | HTML | 0 |
1 1 | Characters between < and element name | ThomasOrlita | 4/15/2024 | HTML | 1 |
| Characters allowed before javascript URL | ThomasOrlita | 4/15/2024 | JS | 0 |
| Characters that change length on .toUpperCase() | ThomasOrlita | 4/15/2024 | JS | 0 |
| Characters allowed between an object and bracket notation | cold-try | 4/15/2024 | JS | 0 |
| Characters allowed between an object and the dot operator | cold-try | 4/15/2024 | JS | 0 |
| Characters that can be inserted in the middle of the JS protocol name | cold-try | 4/15/2024 | XSS | 0 |
| Characters allowed in-between operators | hackvertor | 4/14/2024 | JS | 2 |
| Characters allowed in-between hyphens | hackvertor | 4/14/2024 | XSS | 0 |
| Characters allowed as a class separator | hackvertor | 4/13/2024 | XSS | 0 |
| Characters that act like new line or single line comment | hackvertor | 4/13/2024 | JS | 0 |