1 | Characters allowed instead of equal sign | c3l3si4n | 4/28/2024 | XSS | 0 |
| Entities allowed as JS variables | hackvertor | 7/2/2024 | XSS | 1 |
| Entities that cause an external URL before @ | hackvertor | 9/25/2024 | XSS | 4 |
| Characters ignored in an attribute name | hackvertor | 5/28/2024 | XSS | 0 |
| Characters that act as attribute quotes copy | freddyb | 5/31/2024 | XSS | 0 |
| Entities allowed before function calls | hackvertor | 7/2/2024 | XSS | 0 |
| Quotes | dogspyagent | 7/13/2024 | XSS | 0 |
1 | Characters that can break out of an inline style with double quotes | 0xdef1ant | 7/13/2024 | XSS | 0 |
9 | XSS vectors that consume tag | Y4tacker | 11/5/2024 | XSS | 1 |
1143 | Mutated XSS Attributes | IDKdir | 7/13/2024 | XSS | 0 |
| Characters that close or encapsulate HTML attribute values | ola456 | 11/5/2024 | XSS | 1 |
31 | Characters allowed after greater than in events | hackvertor | 6/21/2024 | XSS | 0 |
7 7 | Fuzzing weird script behaviour after script text | hackvertor | 7/18/2024 | XSS | 0 |
| Characters that cause the backslash to be consumed with GBK charset | hackvertor | 11/7/2024 | XSS | 0 |
| Mutated XSS with img onerror | sqjor | 7/30/2024 | XSS | 0 |
| characters after slash that make a http protocol | InsertScript | 4/3/2024 | XSS | 0 |
| framers event executors | weizman | 4/10/2024 | XSS | 0 |
4 | HTML elements that inherit properties which return the full URL | 0x999-x | 11/14/2024 | XSS | 0 |
| Chars allowed before domain | t0xodile | 9/24/2024 | XSS | 0 |
127 | HTML TAGS Lists | Y4tacker | 1/3/2025 | XSS | 0 |