7 7 | Fuzzing weird script behaviour after script text | hackvertor | 7/18/2024 | XSS | 0 |
| HTML elements that are self closing or different text content | hackvertor | 4/19/2024 | XSS | 2 |
| Characters allowed in colon entity | InsertScript | 9/19/2024 | XSS | 0 |
| Tags that remove the span or are self closing | hackvertor | 7/16/2024 | XSS | 0 |
| Entities that cause an external URL before @ | hackvertor | 9/25/2024 | XSS | 4 |
| DOM element relationships | joaxcar | 4/10/2024 | XSS | 0 |
9 | XSS vectors that consume tag | Y4tacker | 11/5/2024 | XSS | 1 |
| Characters that close or encapsulate HTML attribute values | ola456 | 11/5/2024 | XSS | 1 |
| Character allowed after onerror event | InsertScript | 4/2/2024 | XSS | 0 |
| Characters that cause the backslash to be consumed with GBK charset | hackvertor | 11/7/2024 | XSS | 0 |
4 | HTML elements that inherit properties which return the full URL | 0x999-x | 11/14/2024 | XSS | 0 |
| ISO-2022-JP ASCII escape sequence | hackvertor | 12/11/2024 | XSS | 1 |
| Characters in-between square brackets that close cdata | hackvertor | 10/8/2024 | XSS | 0 |
127 | HTML TAGS Lists | Y4tacker | 1/3/2025 | XSS | 0 |
5 | Characters allowed between multiple HTML attributes | JorianWoltjer | 9/12/2024 | XSS | 2 |
| Entities that convert to less than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |