| Characters in-between square brackets that close cdata | hackvertor | 10/8/2024 | XSS | 0 |
4 | HTML elements that inherit properties which return the full URL | 0x999-x | 11/14/2024 | XSS | 0 |
1 1 | < removal bypass | Device1306 | 10/9/2024 | HTML | 0 |
5 | Chars allowed between src and = in img tag | rootd4ddy | 3/2/2025 | XSS | 0 |
| Characters that cause the backslash to be consumed with a big5 charset | hackvertor | 11/1/2024 | XSS | 0 |
106 106 | Tags that support HTML comments | hackvertor | 1/26/2025 | XSS | 0 |
20 | Difference between browser-supported handlers and Shazzer 'events' list | hansmach1ne | 1/5/2025 | JS | 0 |
| Characters allowed after colon which result in an external URL | hackvertor | 1/16/2025 | XSS | 0 |
31 | Characters appended at the end of TLD within URL, which yield in the same host property | InsertScript | 1/10/2025 | JS | 0 |
| Characters transformed when using lowercase | hackvertor | 11/18/2024 | JS | 0 |
| Characters allowed as a class separator | hackvertor | 4/13/2024 | XSS | 0 |
24 | Characters that can be used in eval to write code in between | m-boll | 5/12/2024 | JS | 0 |
| Bypasses for __proto__ string match | vitorfhc | 8/29/2024 | JS | 0 |
2 | Bytes that will normalize ISO-2022-JP | Cillian-Collins | 12/26/2024 | XSS | 1 |
4 | Entities allowed between two forward slashes | InsertScript | 9/19/2024 | XSS | 1 |
2 | Bytes that will scramble ISO-2022-JP | Cillian-Collins | 12/26/2024 | XSS | 1 |
| Characters not urlencoded when using the credentials part of the URL | hackvertor | 5/28/2024 | JS | 1 |
2 | JIS X 0208 bytes that produce ASCII characters | JorianWoltjer | 9/22/2024 | JS | 1 |
| Characters unencoded characters supported in the hash | hackvertor | 9/24/2024 | JS | 1 |
| All events on window | hackvertor | 5/31/2024 | JS | 1 |