1 | Characters that can break out of an inline style with single quotes | 0xdef1ant | 7/13/2024 | XSS | 0 |
2 2 | HTML entities before JavaScript URL | hackvertor | 6/25/2024 | JS | 0 |
| Characters after strings | hackvertor | 4/3/2024 | JS | 0 |
1 1 | XSS vectors that execute automatically inside math | hackvertor | 4/17/2024 | XSS | 0 |
| characters after slash that make a http protocol | InsertScript | 4/3/2024 | XSS | 0 |
1 | Characters allowed to break double quotes | p3n7a90n | 6/30/2024 | XSS | 0 |
| HTML comment before greater than | hackvertor | 3/30/2024 | HTML | 0 |
| Entities allowed before function calls | hackvertor | 7/2/2024 | XSS | 0 |
| Mutated XSS with img onerror | sqjor | 7/30/2024 | XSS | 0 |
| Entities allowed between function call and number | hackvertor | 7/2/2024 | XSS | 0 |
1 | Characters allowed instead of equal sign | c3l3si4n | 4/28/2024 | XSS | 0 |
| Characters that are valid JS variables | hackvertor | 4/29/2024 | JS | 0 |
| Host | IDKdir | 7/15/2024 | JS | 0 |
| Entities that convert to greater than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Entities that convert to less than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Tags that HTML encode it's contents | hackvertor | 7/16/2024 | XSS | 0 |
| Entities allowed after slashes on a protocol relative URL | hackvertor | 7/6/2024 | JS | 0 |
| JavaScript separators between function names | InsertScript | 4/2/2024 | JS | 0 |
| Characters allowed as a class separator | hackvertor | 4/13/2024 | XSS | 0 |
| Characters to break out from eval string | m-boll | 5/12/2024 | JS | 0 |