| Entities that are normalized for e | hackvertor | 7/12/2024 | JS | 0 |
| Quotes | dogspyagent | 7/13/2024 | XSS | 0 |
29 | Characters allowed after the void operator | hackvertor | 4/30/2024 | JS | 0 |
| HTML-Encoded Attribute Escape | IDKdir | 7/13/2024 | XSS | 0 |
1 | Characters that can break out of an inline style with double quotes | 0xdef1ant | 7/13/2024 | XSS | 0 |
| Characters allowed between HTML attributes | 0x999-x | 4/10/2024 | XSS | 0 |
| Attributes that are also DOM properties | hackvertor | 4/30/2024 | XSS | 0 |
1 | Characters that can break out of an inline style with single quotes | 0xdef1ant | 7/13/2024 | XSS | 0 |
5 5 | Characters allowed before the tag attribute and equals. | hansmach1ne | 4/30/2024 | HTML | 0 |
1143 | Mutated XSS Attributes | IDKdir | 7/13/2024 | XSS | 0 |
| Character allowed after onerror event | InsertScript | 4/2/2024 | XSS | 0 |
| Break out of CSS strings | hackvertor | 4/4/2024 | HTML | 0 |
8 | Characters that expand upon toUpperCase() | DreyAnd | 4/10/2024 | JS | 0 |
14 | Active formatting elements | JorianWoltjer | 5/1/2024 | XSS | 0 |
| Host | IDKdir | 7/15/2024 | JS | 0 |
5 5 | Characters allowed before CSS selectors | hackvertor | 7/15/2024 | XSS | 0 |
32 | Characters that can precede the javascript protocol copy | rcbarnett | 5/2/2024 | XSS | 0 |
| React DOM src | IDKdir | 7/15/2024 | JS | 0 |
25 | Characters allowed before optional chaining | hackvertor | 5/4/2024 | JS | 0 |
| Tags that HTML encode it's contents | hackvertor | 7/16/2024 | XSS | 0 |