| Find WAF bypass for eval context | elieehel | 11/22/2024 | JS | 0 |
| Characters allowed after parentheses | hackvertor | 4/1/2024 | JS | 0 |
4 4 | Characters that can break out of a single line comment | 0x999-x | 4/10/2024 | JS | 0 |
| Characters that separate CSS properties | hackvertor | 4/2/2024 | HTML | 0 |
25 25 | Characters allowed between variable name and equals sign | 0x999-x | 4/9/2024 | JS | 0 |
| Characters allowed between HTML attributes | 0x999-x | 4/10/2024 | XSS | 0 |
25 | Valid characters between function and parenthesis | felipecaon | 5/6/2024 | JS | 0 |
| Characters allowed before javascript URL | ThomasOrlita | 4/15/2024 | JS | 0 |
| Characters that can be inserted in the middle of the JS protocol name | cold-try | 4/15/2024 | XSS | 0 |
| XSS vectors that execute automatically | hackvertor | 4/17/2024 | XSS | 0 |
1 | Characters that can break out of an inline style with single quotes | 0xdef1ant | 7/13/2024 | XSS | 0 |
| Entities allowed before slashes on a protocol relative URL | hackvertor | 7/6/2024 | JS | 0 |
1 | work | nu11secur1ty | 9/29/2024 | HTML | 0 |
| HTML-Encoded Attribute Escape | IDKdir | 7/13/2024 | XSS | 0 |
9 | Entities allowed inside host | hackvertor | 7/6/2024 | JS | 0 |
| DOM element relationships | joaxcar | 4/10/2024 | XSS | 0 |
| Characters in-between square brackets that close cdata | hackvertor | 10/8/2024 | XSS | 0 |
1 | Bypass __proto__ string match defense | vitorfhc | 8/29/2024 | JS | 0 |
| Characters that act as quotes or whitespace | hackvertor | 4/13/2024 | HTML | 0 |
1 1 | XSS vectors that execute automatically inside math | hackvertor | 4/17/2024 | XSS | 0 |