| characters after slash that make a http protocol | InsertScript | 4/3/2024 | XSS | 0 |
| framers event executors | weizman | 4/10/2024 | XSS | 0 |
1 | Characters that can break out of an inline style with single quotes | 0xdef1ant | 7/13/2024 | XSS | 0 |
| Entities that convert to greater than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Characters allowed in-between hyphens | hackvertor | 4/14/2024 | XSS | 1 |
| Tags that HTML encode it's contents | hackvertor | 7/16/2024 | XSS | 0 |
| Characters allowed after malformed entities | hackvertor | 7/1/2024 | XSS | 0 |
9 | XSS vectors that consume tag | Y4tacker | 11/5/2024 | XSS | 1 |
32 | Characters that can precede the javascript protocol copy | rcbarnett | 5/2/2024 | XSS | 0 |
31 | Characters allowed after greater than in events | hackvertor | 6/21/2024 | XSS | 0 |
4 | Entities allowed between two forward slashes | InsertScript | 9/19/2024 | XSS | 1 |
| Characters that can be inserted in the middle of the JS protocol name | cold-try | 4/15/2024 | XSS | 0 |
| Characters allowed in colon entity | InsertScript | 9/19/2024 | XSS | 0 |
1 | Characters that can break out of an inline style background-image url | 0xdef1ant | 7/13/2024 | XSS | 1 |
| Entities that cause an external URL before @ | hackvertor | 9/25/2024 | XSS | 4 |
| Characters that cause the backslash to be consumed with GBK charset | hackvertor | 11/7/2024 | XSS | 0 |
| Characters that close or encapsulate HTML attribute values | ola456 | 11/5/2024 | XSS | 1 |
| Entities allowed between function calls | hackvertor | 6/29/2024 | XSS | 0 |
6 | Characters allowed before onerror events | hackvertor | 3/30/2024 | XSS | 0 |
| Characters that act as attribute quotes | hackvertor | 5/28/2024 | XSS | 0 |