| Characters allowed in path traversal | joaxcar | 8/26/2024 | JS | 0 |
| Characters allowed after slashes which result in an external URL | hackvertor | 1/16/2025 | XSS | 0 |
| Characters that act as attribute quotes | hackvertor | 5/28/2024 | XSS | 0 |
| Entities allowed before slashes which result in an external URL | hackvertor | 1/16/2025 | XSS | 0 |
| Characters allowed in colon entity | InsertScript | 9/19/2024 | XSS | 0 |
| Characters that cause the backslash to be consumed with a big5 charset | hackvertor | 11/1/2024 | XSS | 0 |
| Characters urlencoded that get transformed when using the credentials part of the URL | hackvertor | 9/24/2024 | JS | 0 |
| Characters allowed before the JavaScript protocol | hackvertor | 1/16/2025 | XSS | 0 |
| Window properties | hackvertor | 5/31/2024 | JS | 0 |
| Characters allowed before parentheses | hackvertor | 3/31/2024 | JS | 0 |
| Characters that can be inserted in the middle of the JS protocol name | cold-try | 4/15/2024 | XSS | 0 |
| Characters allowed between slashes using XSS type | hackvertor | 1/16/2025 | XSS | 0 |
106 106 | Tags that support HTML comments | hackvertor | 1/26/2025 | XSS | 0 |
| Tags that get moved out of parent | hackvertor | 1/22/2025 | XSS | 0 |
127 | HTML TAGS Lists | Y4tacker | 1/3/2025 | XSS | 0 |
2.1k | Chars in href that will not default to full URL | joaxcar | 11/16/2024 | XSS | 0 |
| Characters that cause the backslash to be consumed with GBK charset | hackvertor | 11/7/2024 | XSS | 0 |
| Characters allowed as a class separator | hackvertor | 4/13/2024 | XSS | 0 |
24 | Characters that can be used in eval to write code in between | m-boll | 5/12/2024 | JS | 0 |
| Bypasses for __proto__ string match | vitorfhc | 8/29/2024 | JS | 0 |