1 1 | < removal bypass | Device1306 | 10/9/2024 | HTML | 0 |
| Characters allowed after * in CSS comments | hackvertor | 3/31/2024 | HTML | 0 |
| Characters that cause the backslash to be consumed with a big5 charset | hackvertor | 11/1/2024 | XSS | 0 |
| Characters that can precede the javascript protocol copy2 | PinkDraconian | 11/7/2024 | XSS | 0 |
32 | Characters that can precede the javascript protocol copy | rcbarnett | 5/2/2024 | XSS | 0 |
2 2 | HTML entities before JavaScript URL | hackvertor | 6/25/2024 | JS | 0 |
| Character that closes HTML tag | InsertScript | 4/2/2024 | HTML | 0 |
2124 | Chars in href that will not default to full URL | joaxcar | 11/16/2024 | XSS | 0 |
| Characters transformed when using lowercase | hackvertor | 11/18/2024 | JS | 0 |
| Characters allowed between in operator | hackvertor | 4/3/2024 | JS | 0 |
| Impossible lab frameset | renniepak | 11/27/2024 | HTML | 0 |
3 | Characters allowed between slashes | hackvertor | 4/8/2024 | JS | 0 |
20 | Difference between browser-supported handlers and Shazzer 'events' list | hansmach1ne | 1/5/2025 | JS | 0 |
16 | Difference between browser-supported handlers and Shazzer 'all_browser_events' list | hansmach1ne | 1/5/2025 | JS | 0 |
25 | Loose comparison, characters appended which still result in type coercion | hansmach1ne | 1/6/2025 | JS | 0 |
| Characters allowed after parentheses | hackvertor | 4/1/2024 | JS | 0 |
25 | Characters allowed before optional chaining | hackvertor | 5/4/2024 | JS | 0 |
| Entities allowed between function calls | hackvertor | 6/29/2024 | XSS | 0 |
4 4 | Characters that can break out of a single line comment | 0x999-x | 4/10/2024 | JS | 0 |
| JavaScript separators between function names | InsertScript | 4/2/2024 | JS | 0 |