| Characters that act as quotes or whitespace | hackvertor | 4/13/2024 | HTML | 0 |
| Entities that convert to less than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Characters transformed when using uppercase | hackvertor | 11/18/2024 | JS | 0 |
| Entities that convert to greater than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Characters not urlencoded when using the credentials part of the URL | hackvertor | 5/28/2024 | JS | 1 |
| Tags that stop style | hackvertor | 4/9/2024 | HTML | 0 |
| Entities allowed before slashes which result in an external URL | hackvertor | 1/16/2025 | XSS | 0 |
| Characters that act like new line or single line comment | hackvertor | 4/13/2024 | JS | 0 |
| HTML tags that force HTML mode inside SVG | hackvertor | 8/2/2024 | XSS | 1 |
| Characters that cause an external URL before @ | hackvertor | 9/25/2024 | JS | 3 |
| Characters allowed after slashes which result in an external URL | hackvertor | 1/16/2025 | XSS | 0 |
| Consuming tags | hackvertor | 4/8/2024 | HTML | 1 |
| Characters allowed as a class separator | hackvertor | 4/13/2024 | XSS | 0 |
| Characters allowed before event in attribute name using setAttribute | hackvertor | 8/21/2024 | JS | 0 |
| Characters that act as attribute quotes copy | freddyb | 5/31/2024 | XSS | 0 |
| All properties on navigator (two levels of nesting deep) | freddyb | 6/6/2024 | JS | 0 |
| Characters allowed between < and element | felipecaon | 5/6/2024 | HTML | 0 |
25 | Valid characters between function and parenthesis | felipecaon | 5/6/2024 | JS | 0 |
1 | Valid characters between function and dot-parenthesis .() | felipecaon | 5/6/2024 | JS | 0 |
| Find WAF bypass for eval context | elieehel | 11/22/2024 | JS | 0 |