All VectorsVector nameUser Created Type Likes 4 4 4Entities allowed before slashes which result in an external URLhackvertor1/16/2025XSS0 18 18 18Entities allowed between function call and numberhackvertor7/2/2024XSS0 8 4 2Entities allowed between function callshackvertor6/29/2024XSS0 4 4 4Entities allowed between slashes on a protocol relative URLhackvertor7/6/2024JS0 4 4 4Entities allowed between slashes using XSS typehackvertor1/16/2025XSS0 4Entities allowed between two forward slashesInsertScript9/19/2024XSS1Entities allowed inside function namehackvertor7/2/2024XSS0 9Entities allowed inside hosthackvertor7/6/2024JS0Entities in-between square brackets that close cdatahackvertor10/8/2024XSS1 35 35 35Entities still parsed in uppercasehackvertor7/2/2024JS0 10 10 10Entities that are normalized for ehackvertor7/12/2024JS0 4 4 4Entities that cause an external URL before @hackvertor9/25/2024XSS4 3 3 3Entities that convert to greater than in a iframe srcdochackvertor8/1/2024XSS0 3 3 3Entities that convert to less than in a iframe srcdochackvertor8/1/2024XSS0 1 1Escape inline double quotelUcgryy3/7/2025XSS0Find WAF bypass for eval contextelieehel11/22/2024JS0 33Fuzzing for Max sanitized input (simplified)vitorfhc4/7/2025XSS0 7 7 7Fuzzing weird script behaviour after script texthackvertor7/18/2024XSS0 127HTML TAGS ListsY4tacker1/3/2025XSS0 3 3 3HTML comment before greater thanhackvertor3/30/2024HTML0Found 233 recordsPage 8 of 12«3456789101112»