| Find WAF bypass for eval context | elieehel | 11/22/2024 | JS | 0 |
33 | Fuzzing for Max sanitized input (simplified) | vitorfhc | 4/7/2025 | XSS | 0 |
7 7 | Fuzzing weird script behaviour after script text | hackvertor | 7/18/2024 | XSS | 0 |
127 | HTML TAGS Lists | Y4tacker | 1/3/2025 | XSS | 0 |
| HTML comment before greater than | hackvertor | 3/30/2024 | HTML | 0 |
| HTML elements that are self closing or different text content | hackvertor | 4/19/2024 | XSS | 2 |
4 | HTML elements that inherit properties which return the full URL | 0x999-x | 11/14/2024 | XSS | 0 |
| HTML elements that parse differently when rendered | hackvertor | 4/19/2024 | XSS | 1 |
2 2 | HTML entities before JavaScript URL | hackvertor | 6/25/2024 | JS | 0 |
| HTML entities inside JavaScript URL | hackvertor | 6/25/2024 | JS | 0 |
| HTML entities inside JavaScript URL before colon | hackvertor | 6/25/2024 | JS | 0 |
| HTML entities that create ASCII characters inside a JavaScript URL | hackvertor | 6/25/2024 | JS | 4 |
20 | HTML tags and attributes that can be used to access the URL | 0x999-x | 11/4/2024 | XSS | 1 |
2 | HTML tags that can clobber the credentials part of the URL | 0x999-x | 11/4/2024 | XSS | 1 |
| HTML tags that force HTML mode inside SVG | hackvertor | 8/2/2024 | XSS | 1 |
1 | HTML vector | nu11secur1ty | 9/29/2024 | HTML | 0 |
| HTML-Encoded Attribute Escape | IDKdir | 7/13/2024 | XSS | 0 |
| Host | IDKdir | 7/15/2024 | JS | 0 |
| ISO-2022-JP ASCII escape sequence | hackvertor | 12/11/2024 | XSS | 1 |
| Impossible lab frameset | renniepak | 11/27/2024 | HTML | 0 |