| Characters that act as attribute quotes | hackvertor | 5/28/2024 | XSS | 0 |
4 | Entities allowed between two forward slashes | InsertScript | 9/19/2024 | XSS | 1 |
| Characters allowed in colon entity | InsertScript | 9/19/2024 | XSS | 0 |
| Characters that act as attribute quotes copy | freddyb | 5/31/2024 | XSS | 0 |
5 | Characters allowed between multiple HTML attributes | JorianWoltjer | 9/12/2024 | XSS | 2 |
| Characters allowed in-between hyphens | hackvertor | 4/14/2024 | XSS | 0 |
| Chars allowed before domain | t0xodile | 9/24/2024 | XSS | 0 |
| Characters that can be inserted in the middle of the JS protocol name | cold-try | 4/15/2024 | XSS | 0 |
| Entities that cause an external URL before @ | hackvertor | 9/25/2024 | XSS | 4 |
| DOM element relationships | joaxcar | 4/10/2024 | XSS | 0 |
31 | Characters allowed after greater than in events | hackvertor | 6/21/2024 | XSS | 0 |
| Valid characters before domain 1 | avlidienbrunn | 4/10/2024 | XSS | 0 |
| XSS vectors that execute automatically | hackvertor | 4/17/2024 | XSS | 0 |
1 1 | XSS vectors that execute automatically inside svg | hackvertor | 4/17/2024 | XSS | 0 |
| Entities allowed between function calls | hackvertor | 6/29/2024 | XSS | 0 |
| framers event executors | weizman | 4/10/2024 | XSS | 0 |
1 1 | XSS vectors that execute automatically inside math | hackvertor | 4/17/2024 | XSS | 0 |
1 | Characters allowed to break double quotes | p3n7a90n | 6/30/2024 | XSS | 0 |
| Characters allowed after malformed entities | hackvertor | 7/1/2024 | XSS | 0 |
| HTML elements that parse differently when rendered | hackvertor | 4/19/2024 | XSS | 1 |