| test_protocol | winterisland0710 | 5/20/2025 | JS | 0 |
| framers event executors | weizman | 4/10/2024 | XSS | 0 |
1 | Bypass __proto__ string match defense | vitorfhc | 8/29/2024 | JS | 0 |
| Bypasses for __proto__ string match | vitorfhc | 8/29/2024 | JS | 0 |
33 | Fuzzing for Max sanitized input (simplified) | vitorfhc | 4/7/2025 | XSS | 0 |
| Attribute separators | tr3w | 5/6/2024 | HTML | 0 |
| Chars allowed before domain | t0xodile | 9/24/2024 | XSS | 0 |
| Characters allowed to end a JS string | sqjor | 7/17/2024 | JS | 0 |
| Mutated XSS with img onerror | sqjor | 7/30/2024 | XSS | 0 |
17 | URL scheme separator alternatives | simoneonofri | 11/14/2024 | JS | 1 |
5 | Chars allowed between src and = in img tag | rootd4ddy | 3/2/2025 | XSS | 0 |
30 | Characters Allowed Between Protocol // and localhost Where Host Still Equals localhost | rootd4ddy | 3/2/2025 | JS | 0 |
| Impossible lab frameset | renniepak | 11/27/2024 | HTML | 0 |
3 3 | Characters allowed javascript and colon | renniepak | 4/9/2024 | JS | 3 |
32 32 | Characters that can precede the javascript protocol | renniepak | 4/10/2024 | XSS | 3 |
32 | Characters that can precede the javascript protocol copy | rcbarnett | 5/2/2024 | XSS | 0 |
1 | Characters allowed to break double quotes | p3n7a90n | 6/30/2024 | XSS | 0 |
| Characters that end unencapsulated HTML attribute values | ola456 | 5/14/2025 | XSS | 0 |
| Characters ending XML Processing Instructions (WIP) | ola456 | 2/4/2025 | XSS | 0 |
| Characters that close or encapsulate HTML attribute values | ola456 | 11/5/2024 | XSS | 1 |