| Differences between escape vs encodeURIComponent | hackvertor | 10/15/2024 | JS | 1 |
| Characters allowed at IPv6 but don't change the hostname | d0ge | 6/10/2024 | JS | 1 |
2 | HTML tags that can clobber the credentials part of the URL | 0x999-x | 11/4/2024 | XSS | 1 |
20 | HTML tags and attributes that can be used to access the URL | 0x999-x | 11/4/2024 | XSS | 1 |
| Characters allowed at hostname | d0ge | 6/11/2024 | JS | 1 |
9 | XSS vectors that consume tag | Y4tacker | 11/5/2024 | XSS | 1 |
1 1 | Characters between < and element name | ThomasOrlita | 4/15/2024 | HTML | 1 |
| Characters that close or encapsulate HTML attribute values | ola456 | 11/5/2024 | XSS | 1 |
17 | URL scheme separator alternatives | simoneonofri | 11/14/2024 | JS | 1 |
| Characters that act as new lines in multi line strings | hackvertor | 6/20/2024 | JS | 1 |
29 | Non-standard characters that break JSON.parse() | DreyAnd | 11/15/2024 | JS | 1 |
| ISO-2022-JP ASCII escape sequence | hackvertor | 12/11/2024 | XSS | 1 |
30 30 | Characters allowed after equals sign for event | YouGina | 12/17/2024 | XSS | 1 |
2 | Bytes that will normalize ISO-2022-JP | Cillian-Collins | 12/26/2024 | XSS | 1 |
2 | Bytes that will scramble ISO-2022-JP | Cillian-Collins | 12/26/2024 | XSS | 1 |
| Characters allowed before slashes which result in an external URL | hackvertor | 1/16/2025 | XSS | 1 |
| HTML elements that parse differently when rendered | hackvertor | 4/19/2024 | XSS | 1 |
| Entities allowed as JS variables | hackvertor | 7/2/2024 | XSS | 1 |
| Characters allowed within a hostname but don't change the hostname | ThomasOrlita | 4/30/2024 | JS | 1 |
1 | Characters that can break out of an inline style background-image url | 0xdef1ant | 7/13/2024 | XSS | 1 |