All categories
Browser Quirks
CSS Parsing
Character Encoding
DOM Behavior
Entity Parsing
HTML Parsing
JavaScript Syntax
Regular Expressions
URL Handling
Web APIs
XML Parsing
XSS Execution
Login
Home
Vectors
Categories
All vectors
All collections
Browser diffs
RSS
Stats
Performance
Features
Differences
Releases
Network
Tools
Cheat sheet
Unicode table
Blog
Blog home
RSS
Help
Home
Vectors
Categories
All vectors
All collections
Browser diffs
RSS
Stats
Performance
Features
Differences
Releases
Network
Tools
Cheat sheet
Unicode table
Blog
Blog home
RSS
Help
Smashing...
disconnected
Distributed Fuzzing
Enabled:
Status:
disconnected
Your browser automatically contributes to distributed fuzzing when idle.
Advanced
All categories
Browser Quirks
CSS Parsing
Character Encoding
DOM Behavior
Entity Parsing
HTML Parsing
JavaScript Syntax
Regular Expressions
URL Handling
Web APIs
XML Parsing
XSS Execution
All Vectors
Vector name
User
Created
Type
Likes
1
1
1
1
Characters that can break out of an inline style background-image url
0xdef1ant
7/13/2024
XSS
1
7
7
7
7
Characters ignored in an attribute name
hackvertor
5/28/2024
XSS
0
127
127
127
HTML TAGS Lists
Y4tacker
1/3/2025
XSS
0
1
1
1
Chars allowed before domain
t0xodile
9/24/2024
XSS
0
1
1
1
Characters that can break out of an inline style with single quotes
0xdef1ant
7/13/2024
XSS
0
1
1
1
Entities in-between square brackets that close cdata
hackvertor
10/8/2024
XSS
1
1
1
1
Characters that can break out of an inline style with double quotes
0xdef1ant
7/13/2024
XSS
0
1.1k
1.1k
1.1k
Mutated XSS Attributes
IDKdir
7/13/2024
XSS
0
⚠ Browser differences
16
16
16
2
Entities allowed between function calls
hackvertor
6/29/2024
XSS
0
71.3k
71.3k
71.3k
71.3k
Characters that cause the backslash to be consumed with a big5 charset
hackvertor
11/1/2024
XSS
0
32
32
32
32
Characters that can precede the javascript protocol
renniepak
4/10/2024
XSS
4
31
31
31
31
Characters allowed after malformed entities
hackvertor
7/1/2024
XSS
1
19
19
19
19
Entities allowed before function calls
hackvertor
7/2/2024
XSS
0
3
3
3
3
ISO-2022-JP ASCII escape sequence
hackvertor
12/11/2024
XSS
1
1
1
1
Entities allowed inside function name
hackvertor
7/2/2024
XSS
0
2
2
2
2
Characters that act as attribute quotes copy
freddyb
5/31/2024
XSS
0
8
8
8
8
DOM element relationships
joaxcar
4/10/2024
XSS
0
5
5
5
5
Character allowed after onerror event
InsertScript
4/2/2024
XSS
0
1
1
1
1
Characters in-between square brackets that close cdata
hackvertor
10/8/2024
XSS
0
19
19
19
19
HTML tags and attributes that can be used to access the URL
0x999-x
11/4/2024
XSS
1
Found
314
records
Page 3 of 16
«
1
2
3
4
5
6
7
8
9
10
»