1 | Characters that can break out of an inline style with single quotes | 0xdef1ant | 7/13/2024 | XSS | 0 |
1 | Characters that can break out of an inline style with double quotes | 0xdef1ant | 7/13/2024 | XSS | 0 |
| HTML-Encoded Attribute Escape | IDKdir | 7/13/2024 | XSS | 0 |
| Quotes | dogspyagent | 7/13/2024 | XSS | 0 |
| Entities that are normalized for e | hackvertor | 7/12/2024 | JS | 0 |
9 | Entities allowed inside host | hackvertor | 7/6/2024 | JS | 0 |
| Entities allowed before slashes on a protocol relative URL | hackvertor | 7/6/2024 | JS | 0 |
| Entities allowed after slashes on a protocol relative URL | hackvertor | 7/6/2024 | JS | 0 |
| Entities allowed between slashes on a protocol relative URL | hackvertor | 7/6/2024 | JS | 0 |
| Entities allowed as JS variables | hackvertor | 7/2/2024 | XSS | 0 |
| Entities still parsed in uppercase | hackvertor | 7/2/2024 | JS | 0 |
| Entities allowed between function call and number | hackvertor | 7/2/2024 | XSS | 0 |
| Entities allowed inside function name | hackvertor | 7/2/2024 | XSS | 0 |
| Entities allowed before function calls | hackvertor | 7/2/2024 | XSS | 0 |
| Characters allowed after malformed entities | hackvertor | 7/1/2024 | XSS | 0 |
1 | Characters allowed to break double quotes | p3n7a90n | 6/30/2024 | XSS | 0 |
| Entities allowed between function calls | hackvertor | 6/29/2024 | XSS | 0 |
| JavaScript Scheme starting with https:// | BinaryScary | 6/28/2024 | JS | 4 |
| HTML entities that create ASCII characters inside a JavaScript URL | hackvertor | 6/25/2024 | JS | 2 |
2 | HTML entities before JavaScript URL | hackvertor | 6/25/2024 | JS | 0 |