127 | HTML TAGS Lists | Y4tacker | 1/3/2025 | XSS | 0 |
| Characters allowed in-between hyphens | hackvertor | 4/14/2024 | XSS | 1 |
| Valid characters before domain 1 | avlidienbrunn | 4/10/2024 | XSS | 0 |
| Characters allowed after malformed entities | hackvertor | 7/1/2024 | XSS | 0 |
6 | Characters allowed before onerror events | hackvertor | 3/30/2024 | XSS | 0 |
7 7 | Fuzzing weird script behaviour after script text | hackvertor | 7/18/2024 | XSS | 0 |
1 | Characters that can break out of an inline style with single quotes | 0xdef1ant | 7/13/2024 | XSS | 0 |
| Mutated XSS with img onerror | sqjor | 7/30/2024 | XSS | 0 |
| Entities that convert to greater than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Chars allowed before domain | t0xodile | 9/24/2024 | XSS | 0 |
| Characters allowed in colon entity | InsertScript | 9/19/2024 | XSS | 0 |
| Quotes | dogspyagent | 7/13/2024 | XSS | 0 |
| framers event executors | weizman | 4/10/2024 | XSS | 0 |
| Entities in-between square brackets that close cdata | hackvertor | 10/8/2024 | XSS | 1 |
| Characters that can precede the javascript protocol copy2 | PinkDraconian | 11/7/2024 | XSS | 0 |
20 | HTML tags and attributes that can be used to access the URL | 0x999-x | 11/4/2024 | XSS | 1 |
32 32 | Characters that can precede the javascript protocol | renniepak | 4/10/2024 | XSS | 3 |
| Characters that close or encapsulate HTML attribute values | ola456 | 11/5/2024 | XSS | 1 |
| Characters that act as attribute quotes | hackvertor | 5/28/2024 | XSS | 0 |
1 | Characters that can break out of an inline style background-image url | 0xdef1ant | 7/13/2024 | XSS | 1 |