| Entities allowed before slashes which result in an external URL | hackvertor | 1/16/2025 | XSS | 0 |
| Entities allowed between function call and number | hackvertor | 7/2/2024 | XSS | 0 |
| Entities allowed between function calls | hackvertor | 6/29/2024 | XSS | 0 |
| Entities allowed between slashes on a protocol relative URL | hackvertor | 7/6/2024 | JS | 0 |
| Entities allowed between slashes using XSS type | hackvertor | 1/16/2025 | XSS | 0 |
4 | Entities allowed between two forward slashes | InsertScript | 9/19/2024 | XSS | 1 |
| Entities allowed inside function name | hackvertor | 7/2/2024 | XSS | 0 |
9 | Entities allowed inside host | hackvertor | 7/6/2024 | JS | 0 |
| Entities in-between square brackets that close cdata | hackvertor | 10/8/2024 | XSS | 1 |
| Entities still parsed in uppercase | hackvertor | 7/2/2024 | JS | 0 |
| Entities that are normalized for e | hackvertor | 7/12/2024 | JS | 0 |
| Entities that cause an external URL before @ | hackvertor | 9/25/2024 | XSS | 4 |
| Entities that convert to greater than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Entities that convert to less than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
1 | Escape inline double quote | lUcgryy | 3/7/2025 | XSS | 0 |
| Find WAF bypass for eval context | elieehel | 11/22/2024 | JS | 0 |
7 7 | Fuzzing weird script behaviour after script text | hackvertor | 7/18/2024 | XSS | 0 |
127 | HTML TAGS Lists | Y4tacker | 1/3/2025 | XSS | 0 |
| HTML comment before greater than | hackvertor | 3/30/2024 | HTML | 0 |
| HTML elements that are self closing or different text content | hackvertor | 4/19/2024 | XSS | 2 |