| framers event executors | weizman | 4/10/2024 | XSS | 0 |
1 | Bypass __proto__ string match defense | vitorfhc | 8/29/2024 | JS | 0 |
| Bypasses for __proto__ string match | vitorfhc | 8/29/2024 | JS | 0 |
| Attribute separators | tr3w | 5/6/2024 | HTML | 0 |
| Chars allowed before domain | t0xodile | 9/24/2024 | XSS | 0 |
| Characters allowed to end a JS string | sqjor | 7/17/2024 | JS | 0 |
| Mutated XSS with img onerror | sqjor | 7/30/2024 | XSS | 0 |
17 | URL scheme separator alternatives | simoneonofri | 11/14/2024 | JS | 1 |
30 | Characters Allowed Between Protocol // and localhost Where Host Still Equals localhost | rootd4ddy | 3/2/2025 | JS | 0 |
5 | Chars allowed between src and = in img tag | rootd4ddy | 3/2/2025 | XSS | 0 |
3 3 | Characters allowed javascript and colon | renniepak | 4/9/2024 | JS | 3 |
| Impossible lab frameset | renniepak | 11/27/2024 | HTML | 0 |
32 32 | Characters that can precede the javascript protocol | renniepak | 4/10/2024 | XSS | 3 |
32 | Characters that can precede the javascript protocol copy | rcbarnett | 5/2/2024 | XSS | 0 |
1 | Characters allowed to break double quotes | p3n7a90n | 6/30/2024 | XSS | 0 |
| Characters ending XML Processing Instructions (WIP) | ola456 | 2/4/2025 | XSS | 0 |
| Characters that close or encapsulate HTML attribute values | ola456 | 11/5/2024 | XSS | 1 |
1 | HTML vector | nu11secur1ty | 9/29/2024 | HTML | 0 |
2 | char not urlencoded (data) | nu11secur1ty | 9/29/2024 | JS | 0 |
141 | char not urlencoded (data+) | nu11secur1ty | 9/29/2024 | JS | 0 |