| Characters allowed before slashes which result in an external URL | hackvertor | 1/16/2025 | XSS | 1 |
| framers event executors | weizman | 4/10/2024 | XSS | 0 |
1 | Characters that can break out of an inline style with single quotes | 0xdef1ant | 7/13/2024 | XSS | 0 |
| Entities allowed between function calls | hackvertor | 6/29/2024 | XSS | 0 |
5 5 | Characters allowed before CSS selectors | hackvertor | 7/15/2024 | XSS | 0 |
| Characters allowed after malformed entities | hackvertor | 7/1/2024 | XSS | 1 |
| HTML elements that parse differently when rendered | hackvertor | 4/19/2024 | XSS | 1 |
| Entities allowed inside function name | hackvertor | 7/2/2024 | XSS | 0 |
2 2 | HTML tags that can clobber the credentials part of the URL | 0x999-x | 11/4/2024 | XSS | 1 |
1 1 | Characters allowed instead of equal sign | c3l3si4n | 4/28/2024 | XSS | 0 |
9 | XSS vectors that consume tag | Y4tacker | 11/5/2024 | XSS | 1 |
2.1k | Chars in href that will not default to full URL | joaxcar | 11/16/2024 | XSS | 0 |
| Entities that cause an external URL before @ | hackvertor | 9/25/2024 | XSS | 4 |
| Mutated XSS with img onerror | sqjor | 7/30/2024 | XSS | 0 |
1 | Characters that can break out of an inline style with double quotes | 0xdef1ant | 7/13/2024 | XSS | 0 |
| Characters allowed as a class separator | hackvertor | 4/13/2024 | XSS | 0 |
6 6 | ToUpperCase Improper Character Morphing | IDKdir | 7/13/2024 | JS | 1 |
| Characters allowed in-between operators | hackvertor | 4/14/2024 | JS | 2 |
| Characters not urlencoded when using the credentials part of the URL | hackvertor | 5/28/2024 | JS | 1 |
| Window properties | hackvertor | 5/31/2024 | JS | 0 |