| Mutated XSS with img onerror | sqjor | 7/30/2024 | XSS | 0 |
6 | Allowed characters right after tag name & before tag closure, no other characters in between | hansmach1ne | 1/9/2025 | XSS | 0 |
| characters after slash that make a http protocol | InsertScript | 4/3/2024 | XSS | 0 |
| framers event executors | weizman | 4/10/2024 | XSS | 0 |
4 | HTML elements that inherit properties which return the full URL | 0x999-x | 11/14/2024 | XSS | 0 |
| Chars allowed before domain | t0xodile | 9/24/2024 | XSS | 0 |
127 | HTML TAGS Lists | Y4tacker | 1/3/2025 | XSS | 0 |
| Entities in-between square brackets that close cdata | hackvertor | 10/8/2024 | XSS | 1 |
2 | Bytes that will normalize ISO-2022-JP | Cillian-Collins | 12/26/2024 | XSS | 1 |
| Characters that cause the backslash to be consumed with a big5 charset | hackvertor | 11/1/2024 | XSS | 0 |
20 | HTML tags and attributes that can be used to access the URL | 0x999-x | 11/4/2024 | XSS | 1 |
32 | Characters that can precede the javascript protocol copy | rcbarnett | 5/2/2024 | XSS | 0 |
| Characters that can precede the javascript protocol copy2 | PinkDraconian | 11/7/2024 | XSS | 0 |
2124 | Chars in href that will not default to full URL | joaxcar | 11/16/2024 | XSS | 0 |
| Characters allowed in-between hyphens | hackvertor | 4/14/2024 | XSS | 1 |
30 30 | Characters allowed after equals sign for event | YouGina | 12/17/2024 | XSS | 1 |
| Entities allowed between function calls | hackvertor | 6/29/2024 | XSS | 0 |
| Valid characters before domain 1 | avlidienbrunn | 4/10/2024 | XSS | 0 |
| Characters allowed after malformed entities | hackvertor | 7/1/2024 | XSS | 0 |
32 32 | Characters that can precede the javascript protocol | renniepak | 4/10/2024 | XSS | 3 |