| Characters allowed before event in attribute name using setAttribute | hackvertor | 8/21/2024 | JS | 0 |
| HTML entities that create ASCII characters inside a JavaScript URL | hackvertor | 6/25/2024 | JS | 4 |
| Characters urlencoded that get transformed when using the credentials part of the URL | hackvertor | 9/24/2024 | JS | 0 |
| Characters allowed after parentheses | hackvertor | 4/1/2024 | JS | 0 |
| Entities allowed inside function name | hackvertor | 7/2/2024 | XSS | 0 |
| HTML elements that are self closing or different text content | hackvertor | 4/19/2024 | XSS | 2 |
| Entities allowed between function call and number | hackvertor | 7/2/2024 | XSS | 0 |
| Characters after strings | hackvertor | 4/3/2024 | JS | 0 |
| Characters allowed after malformed entities | hackvertor | 7/1/2024 | XSS | 0 |
| HTML elements that parse differently when rendered | hackvertor | 4/19/2024 | XSS | 1 |
| Differences between escape vs encodeURIComponent | hackvertor | 10/15/2024 | JS | 1 |
| Entities still parsed in uppercase | hackvertor | 7/2/2024 | JS | 0 |
| Entities allowed as JS variables | hackvertor | 7/2/2024 | XSS | 1 |
| Entities allowed between slashes on a protocol relative URL | hackvertor | 7/6/2024 | JS | 0 |
| Characters that are valid JS variables | hackvertor | 4/29/2024 | JS | 0 |
| Entities allowed after slashes on a protocol relative URL | hackvertor | 7/6/2024 | JS | 0 |
| Entities that convert to less than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Characters unencoded characters supported in the hash | hackvertor | 9/24/2024 | JS | 1 |
| Entities that convert to greater than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
661 662 | Characters that can be used as valid labels in JavaScript | hackvertor | 4/30/2024 | JS | 2 |