| Entities that convert to less than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
29 | Characters allowed after the void operator | hackvertor | 4/30/2024 | JS | 0 |
| Break out of CSS strings | hackvertor | 4/4/2024 | HTML | 0 |
| Attributes that are also DOM properties | hackvertor | 4/30/2024 | XSS | 0 |
| Characters that cause an external URL before @ | hackvertor | 9/25/2024 | JS | 3 |
| Characters allowed before event in attribute name using setAttribute | hackvertor | 8/21/2024 | JS | 0 |
12 | Unicode characters that get normalized into path traversal characters | hackvertor | 12/12/2024 | JS | 2 |
| Characters urlencoded that get transformed when using the credentials part of the URL | hackvertor | 9/24/2024 | JS | 0 |
| Consuming tags | hackvertor | 4/8/2024 | HTML | 1 |
5 5 | Characters allowed before CSS selectors | hackvertor | 7/15/2024 | XSS | 0 |
| Characters allowed after * in CSS comments | hackvertor | 3/31/2024 | HTML | 0 |
25 | Characters allowed before optional chaining | hackvertor | 5/4/2024 | JS | 0 |
| Tags that HTML encode it's contents | hackvertor | 7/16/2024 | XSS | 0 |
| Characters transformed when using lowercase | hackvertor | 11/18/2024 | JS | 0 |
25 25 | Characters allowed after optional chaining | hackvertor | 5/4/2024 | JS | 2 |
| Tags that remove the span or are self closing | hackvertor | 7/16/2024 | XSS | 0 |
| Tags that cause child tags not to be found in the DOM | hackvertor | 7/18/2024 | HTML | 0 |
7 7 | Fuzzing weird script behaviour after script text | hackvertor | 7/18/2024 | XSS | 0 |
| Entities that cause an external URL before @ | hackvertor | 9/25/2024 | XSS | 4 |
3 | Characters allowed between slashes | hackvertor | 4/8/2024 | JS | 0 |