3 | Characters allowed between slashes | hackvertor | 4/8/2024 | JS | 0 |
1 1 | XSS vectors that execute automatically inside math | hackvertor | 4/17/2024 | XSS | 0 |
| Entities that are normalized for e | hackvertor | 7/12/2024 | JS | 0 |
| Entities allowed between function calls | hackvertor | 6/29/2024 | XSS | 0 |
9 | Entities allowed inside host | hackvertor | 7/6/2024 | JS | 0 |
| Characters allowed in-between hyphens | hackvertor | 4/14/2024 | XSS | 0 |
| Consuming tags | hackvertor | 4/8/2024 | HTML | 1 |
| Characters allowed after parentheses | hackvertor | 4/1/2024 | JS | 0 |
| Entities that convert to less than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| document properties | hackvertor | 5/31/2024 | JS | 0 |
| Break out of CSS strings | hackvertor | 4/4/2024 | HTML | 0 |
| Characters in-between square brackets that close cdata | hackvertor | 10/8/2024 | XSS | 0 |
| Characters that separate CSS properties | hackvertor | 4/2/2024 | HTML | 0 |
| Characters after strings | hackvertor | 4/3/2024 | JS | 0 |
| Characters allowed after malformed entities | hackvertor | 7/1/2024 | XSS | 0 |
| Characters that act like new line or single line comment | hackvertor | 4/13/2024 | JS | 0 |
| Entities allowed before slashes on a protocol relative URL | hackvertor | 7/6/2024 | JS | 0 |
| Characters allowed as a class separator | hackvertor | 4/13/2024 | XSS | 0 |
| XSS vectors that execute automatically | hackvertor | 4/17/2024 | XSS | 0 |
| HTML elements that parse differently when rendered | hackvertor | 4/19/2024 | XSS | 1 |