1 1 | < removal bypass | Device1306 | 10/9/2024 | HTML | 0 |
14 | Active formatting elements | JorianWoltjer | 5/1/2024 | XSS | 0 |
| All events on window | hackvertor | 5/31/2024 | JS | 1 |
| All properties on navigator (two levels of nesting deep) | freddyb | 6/6/2024 | JS | 0 |
6 | Allowed characters right after tag name & before tag closure, no other characters in between | hansmach1ne | 1/9/2025 | XSS | 0 |
| Attribute separators | tr3w | 5/6/2024 | HTML | 0 |
| Attributes that are also DOM properties | hackvertor | 4/30/2024 | XSS | 0 |
| Break out of CSS strings | hackvertor | 4/4/2024 | HTML | 0 |
1 | Bypass __proto__ string match defense | vitorfhc | 8/29/2024 | JS | 0 |
| Bypasses for __proto__ string match | vitorfhc | 8/29/2024 | JS | 0 |
2 | Bytes that will normalize ISO-2022-JP | Cillian-Collins | 12/26/2024 | XSS | 1 |
2 | Bytes that will scramble ISO-2022-JP | Cillian-Collins | 12/26/2024 | XSS | 1 |
| Character allowed after onerror event | InsertScript | 4/2/2024 | XSS | 0 |
| Character that closes HTML tag | InsertScript | 4/2/2024 | HTML | 0 |
| Characters after strings | hackvertor | 4/3/2024 | JS | 0 |
| Characters allowed after * in CSS comments | hackvertor | 3/31/2024 | HTML | 0 |
30 30 | Characters allowed after equals sign for event | YouGina | 12/17/2024 | XSS | 1 |
31 | Characters allowed after greater than in events | hackvertor | 6/21/2024 | XSS | 0 |
| Characters allowed after hostname but don't change the hostname | ThomasOrlita | 4/15/2024 | JS | 2 |
| Characters allowed after malformed entities | hackvertor | 7/1/2024 | XSS | 0 |