| Properties are accessible in a sandboxed iframe | hackvertor | 6/7/2024 | JS | 0 |
| Characters allowed at hostname | d0ge | 6/11/2024 | JS | 1 |
| Characters ignored in strings when doing a non strict comparison | hackvertor | 6/18/2024 | JS | 0 |
1 | Characters allowed to break double quotes | p3n7a90n | 6/30/2024 | XSS | 0 |
1 1 | XSS vectors that execute automatically inside math | hackvertor | 4/17/2024 | XSS | 0 |
| Entities allowed between function call and number | hackvertor | 7/2/2024 | XSS | 0 |
5 5 | Characters allowed before CSS selectors | hackvertor | 7/15/2024 | XSS | 0 |
| Attributes that are also DOM properties | hackvertor | 4/30/2024 | XSS | 0 |
| Entities that convert to less than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Tags that HTML encode it's contents | hackvertor | 7/16/2024 | XSS | 0 |
5 | Characters allowed between multiple HTML attributes | JorianWoltjer | 9/12/2024 | XSS | 2 |
| Entities that convert to greater than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Characters in-between square brackets that close cdata | hackvertor | 10/8/2024 | XSS | 0 |
4 | Entities allowed between two forward slashes | InsertScript | 9/19/2024 | XSS | 1 |
| Characters allowed in colon entity | InsertScript | 9/19/2024 | XSS | 0 |
| Entities allowed before function calls | hackvertor | 7/2/2024 | XSS | 0 |
| Entities that cause an external URL before @ | hackvertor | 9/25/2024 | XSS | 4 |
| Entities allowed as JS variables | hackvertor | 7/2/2024 | XSS | 1 |
| Quotes | dogspyagent | 7/13/2024 | XSS | 0 |
1 | Characters that can break out of an inline style with double quotes | 0xdef1ant | 7/13/2024 | XSS | 0 |