| Characters that act as array literals | hackvertor | 6/24/2024 | JS | 0 |
3 | Characters allowed between slashes | hackvertor | 4/8/2024 | JS | 0 |
| Tags that cause child tags not to be found in the DOM | hackvertor | 7/18/2024 | HTML | 0 |
| Entities allowed between slashes using XSS type | hackvertor | 1/16/2025 | XSS | 0 |
| Characters allowed after * in CSS comments | hackvertor | 3/31/2024 | HTML | 0 |
7 7 | Fuzzing weird script behaviour after script text | hackvertor | 7/18/2024 | XSS | 0 |
| Characters that act like new line or single line comment | hackvertor | 4/13/2024 | JS | 0 |
| Entities that convert to less than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Entities that convert to greater than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| HTML tags that force HTML mode inside SVG | hackvertor | 8/2/2024 | XSS | 1 |
1 1 | XSS vectors that execute automatically inside svg | hackvertor | 4/17/2024 | XSS | 0 |
| Characters allowed before the JavaScript protocol | hackvertor | 1/16/2025 | XSS | 0 |
| Characters allowed before event in attribute name using setAttribute | hackvertor | 8/21/2024 | JS | 0 |
| Characters cause self closing tag | hackvertor | 7/23/2025 | XSS | 0 |
| Characters allowed as a tag name using DOM APIs | hackvertor | 6/13/2025 | JS | 0 |
| Consuming tags | hackvertor | 4/8/2024 | HTML | 1 |
| Characters allowed in the protocol that still resolve host name | hackvertor | 5/6/2025 | JS | 0 |
| Entities allowed between function calls | hackvertor | 6/29/2024 | XSS | 0 |
| Characters allowed after slashes which result in an external URL | hackvertor | 1/16/2025 | XSS | 0 |
| Characters allowed as a class separator | hackvertor | 4/13/2024 | XSS | 0 |