| Characters that cause an external URL before @ | hackvertor | 9/25/2024 | JS | 3 |
31 | Characters allowed after greater than in events | hackvertor | 6/21/2024 | XSS | 0 |
| Entities that convert to greater than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Characters urlencoded that get transformed when using the credentials part of the URL | hackvertor | 9/24/2024 | JS | 0 |
7 7 | Fuzzing weird script behaviour after script text | hackvertor | 7/18/2024 | XSS | 0 |
| HTML entities inside JavaScript URL | hackvertor | 6/25/2024 | JS | 0 |
| Characters ignored after backslash with multiline string | hackvertor | 6/18/2024 | JS | 0 |
| Characters that act as new lines in multi line strings | hackvertor | 6/20/2024 | JS | 1 |
| Characters transformed when using lowercase | hackvertor | 11/18/2024 | JS | 0 |
| Characters that cause the backslash to be consumed with a big5 charset | hackvertor | 11/1/2024 | XSS | 0 |
| Characters that cause the backslash to be consumed with GBK charset | hackvertor | 11/7/2024 | XSS | 0 |
| Entities in-between square brackets that close cdata | hackvertor | 10/8/2024 | XSS | 1 |
| Characters that act as parentheses | hackvertor | 6/24/2024 | JS | 0 |
| Entities allowed before function calls | hackvertor | 7/2/2024 | XSS | 0 |
| Characters that cause exceptions when URL encoded | hackvertor | 10/3/2024 | JS | 2 |
| Entities allowed as JS variables | hackvertor | 7/2/2024 | XSS | 1 |
| XSS vectors that execute automatically | hackvertor | 4/17/2024 | XSS | 0 |
| Characters transformed when using uppercase | hackvertor | 11/18/2024 | JS | 0 |
| HTML entities inside JavaScript URL before colon | hackvertor | 6/25/2024 | JS | 0 |
| Properties that leak the parent URL even when sandboxed | hackvertor | 6/6/2024 | JS | 0 |