All categories
Browser Quirks
CSS Parsing
Character Encoding
DOM Behavior
Entity Parsing
HTML Parsing
JavaScript Syntax
Regular Expressions
URL Handling
XML Parsing
XSS Execution
Login
Home
Vectors
All vectors
Categories
Browser diffs
RSS
Network
Tools
Cheat sheet
Unicode table
Dynamic template
Blog
Blog home
RSS
Help
Home
Vectors
All vectors
Categories
Browser diffs
RSS
Network
Tools
Cheat sheet
Unicode table
Dynamic template
Blog
Blog home
RSS
Help
Testing...
disconnected
Distributed Fuzzing
Enabled:
Status:
disconnected
Your browser automatically contributes to distributed fuzzing when idle.
All Vectors
Vector name
User
Created
Type
Likes
34
34
34
34
Characters allowed before slashes which result in an external URL
hackvertor
1/16/2025
XSS
1
2
2
2
framers event executors
weizman
4/10/2024
XSS
0
1
1
1
Characters that can break out of an inline style with single quotes
0xdef1ant
7/13/2024
XSS
0
⚠ Browser differences
16
16
16
6
Entities allowed between function calls
hackvertor
6/29/2024
XSS
0
⚠ Browser differences
5
1
5
5
Characters allowed before CSS selectors
hackvertor
7/15/2024
XSS
0
31
31
31
31
Characters allowed after malformed entities
hackvertor
7/1/2024
XSS
1
⚠ Browser differences
34
35
34
34
HTML elements that parse differently when rendered
hackvertor
4/19/2024
XSS
1
1
1
1
Entities allowed inside function name
hackvertor
7/2/2024
XSS
0
1
1
1
1
Characters allowed in between @import
bribes
10/19/2025
XSS
0
1
1
1
Characters allowed instead of equal sign
c3l3si4n
4/28/2024
XSS
0
9
9
9
XSS vectors that consume tag
Y4tacker
11/5/2024
XSS
1
2
2
2
HTML tags that can clobber the credentials part of the URL
0x999-x
11/4/2024
XSS
1
7
7
7
7
Characters that close or encapsulate HTML attribute values
ola456
11/5/2024
XSS
1
6
6
6
6
Chars allowed before style attribute...
t0xodile
10/25/2025
XSS
0
5
5
5
5
Characters allowed before after onerror events
t0xodile
10/23/2025
XSS
1
⚠ Browser differences
2.1k
1
2.1k
Chars in href that will not default to full URL
joaxcar
11/16/2024
XSS
0
4
4
4
4
Entities that cause an external URL before @
hackvertor
9/25/2024
XSS
4
1
1
1
Mutated XSS with img onerror
sqjor
7/30/2024
XSS
0
1
1
1
Characters that can break out of an inline style with double quotes
0xdef1ant
7/13/2024
XSS
0
5
5
5
5
Characters allowed as a class separator
hackvertor
4/13/2024
XSS
0
Found
245
records
Page 5 of 13
«
1
2
3
4
5
6
7
8
9
10
»