| Entities allowed before function calls | hackvertor | 7/2/2024 | XSS | 0 |
| Characters not urlencoded when using the shema part of the URL | d0ge | 9/24/2024 | JS | 0 |
| Entities still parsed in uppercase | hackvertor | 7/2/2024 | JS | 0 |
| All properties on navigator (two levels of nesting deep) | freddyb | 6/6/2024 | JS | 0 |
| Entities allowed between slashes on a protocol relative URL | hackvertor | 7/6/2024 | JS | 0 |
| Quotes | dogspyagent | 7/13/2024 | XSS | 0 |
1 | HTML vector | nu11secur1ty | 9/29/2024 | HTML | 0 |
1 | Characters that can break out of an inline style with double quotes | 0xdef1ant | 7/13/2024 | XSS | 0 |
| Properties that leak the parent URL even when sandboxed | hackvertor | 6/6/2024 | JS | 0 |
1.1k | Mutated XSS Attributes | IDKdir | 7/13/2024 | XSS | 0 |
| React DOM src | IDKdir | 7/15/2024 | JS | 0 |
| Characters allowed to end a JS string | sqjor | 7/17/2024 | JS | 0 |
| Tags that cause child tags not to be found in the DOM | hackvertor | 7/18/2024 | HTML | 0 |
31 | Characters allowed after greater than in events | hackvertor | 6/21/2024 | XSS | 0 |
| Characters that cause the backslash to be consumed with GBK charset | hackvertor | 11/7/2024 | XSS | 0 |
7 7 | Fuzzing weird script behaviour after script text | hackvertor | 7/18/2024 | XSS | 0 |
| Mutated XSS with img onerror | sqjor | 7/30/2024 | XSS | 0 |
1 | Characters that can be between < and script> | m10x | 11/12/2024 | HTML | 0 |
6 | Characters that can work as attribute seperator | Sudistark | 8/17/2024 | JS | 0 |
| Characters that act as parentheses | hackvertor | 6/24/2024 | JS | 0 |