9 | Entities allowed inside host | hackvertor | 7/6/2024 | JS | 0 |
| Window properties | hackvertor | 5/31/2024 | JS | 0 |
| Characters that act as new lines in multi line strings | hackvertor | 6/20/2024 | JS | 1 |
| Properties that contain URLs | hackvertor | 5/31/2024 | JS | 2 |
| Tags that remove the span or are self closing | hackvertor | 7/16/2024 | XSS | 0 |
| Entities allowed between function call and number | hackvertor | 7/2/2024 | XSS | 0 |
| Entities still parsed in uppercase | hackvertor | 7/2/2024 | JS | 0 |
31 | Characters allowed after greater than in events | hackvertor | 6/21/2024 | XSS | 0 |
| Characters allowed after parentheses | hackvertor | 4/1/2024 | JS | 0 |
2 2 | HTML entities before JavaScript URL | hackvertor | 6/25/2024 | JS | 0 |
| Entities allowed as JS variables | hackvertor | 7/2/2024 | XSS | 1 |
| Characters ignored in strings when doing a non strict comparison | hackvertor | 6/18/2024 | JS | 0 |
| Entities allowed inside function name | hackvertor | 7/2/2024 | XSS | 0 |
| Entities allowed before function calls | hackvertor | 7/2/2024 | XSS | 0 |
| HTML elements that are self closing or different text content | hackvertor | 4/19/2024 | XSS | 2 |
1 1 | XSS vectors that execute automatically inside svg | hackvertor | 4/17/2024 | XSS | 0 |
1 1 | XSS vectors that execute automatically inside math | hackvertor | 4/17/2024 | XSS | 0 |
| Entities that convert to less than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Tags that HTML encode it's contents | hackvertor | 7/16/2024 | XSS | 0 |
| Entities allowed between slashes on a protocol relative URL | hackvertor | 7/6/2024 | JS | 0 |