| Impossible lab frameset | renniepak | 11/27/2024 | HTML | 0 |
| Characters to break out from eval string | m-boll | 5/12/2024 | JS | 0 |
| Entities that convert to greater than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Properties are accessible in a sandboxed iframe | hackvertor | 6/7/2024 | JS | 0 |
20 | Difference between browser-supported handlers and Shazzer 'events' list | hansmach1ne | 1/5/2025 | JS | 0 |
| Characters ignored after backslash with multiline string | hackvertor | 6/18/2024 | JS | 0 |
| Characters allowed in colon entity | InsertScript | 9/19/2024 | XSS | 0 |
1 | HTML vector | nu11secur1ty | 9/29/2024 | HTML | 0 |
2124 | Chars in href that will not default to full URL | joaxcar | 11/16/2024 | XSS | 0 |
| Entities allowed before function calls | hackvertor | 7/2/2024 | XSS | 0 |
| Characters not urlencoded when using the shema part of the URL | d0ge | 9/24/2024 | JS | 0 |
| All properties on navigator (two levels of nesting deep) | freddyb | 6/6/2024 | JS | 0 |
16 | Difference between browser-supported handlers and Shazzer 'all_browser_events' list | hansmach1ne | 1/5/2025 | JS | 0 |
| JavaScript separators between function names | InsertScript | 4/2/2024 | JS | 0 |
| Characters allowed after parentheses | hackvertor | 4/1/2024 | JS | 0 |
| Characters urlencoded that get transformed when using the credentials part of the URL | hackvertor | 9/24/2024 | JS | 0 |
7 7 | Fuzzing weird script behaviour after script text | hackvertor | 7/18/2024 | XSS | 0 |
| React DOM src | IDKdir | 7/15/2024 | JS | 0 |
6 | Characters allowed before onerror events | hackvertor | 3/30/2024 | XSS | 0 |
1 1 | XSS vectors that execute automatically inside svg | hackvertor | 4/17/2024 | XSS | 0 |