5 | Characters allowed between multiple HTML attributes | JorianWoltjer | 9/12/2024 | XSS | 2 |
4 | URL domain dot alternatives | JorianWoltjer | 9/10/2024 | JS | 5 |
1 | Bypass __proto__ string match defense | vitorfhc | 8/29/2024 | JS | 0 |
| Bypasses for __proto__ string match | vitorfhc | 8/29/2024 | JS | 0 |
| Characters allowed in path traversal | joaxcar | 8/26/2024 | JS | 0 |
| Characters allowed before event in attribute name using setAttribute | hackvertor | 8/21/2024 | JS | 0 |
6 | Characters that can work as attribute seperator | Sudistark | 8/17/2024 | JS | 0 |
| HTML tags that force HTML mode inside SVG | hackvertor | 8/2/2024 | XSS | 1 |
| Entities that convert to greater than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Entities that convert to less than in a iframe srcdoc | hackvertor | 8/1/2024 | XSS | 0 |
| Mutated XSS with img onerror | sqjor | 7/30/2024 | XSS | 0 |
| Characters that can start an HTML comment | 0x999-x | 7/18/2024 | HTML | 2 |
7 7 | Fuzzing weird script behaviour after script text | hackvertor | 7/18/2024 | XSS | 0 |
| Tags that cause child tags not to be found in the DOM | hackvertor | 7/18/2024 | HTML | 0 |
| Characters allowed to end a JS string | sqjor | 7/17/2024 | JS | 0 |
| Tags that remove the span or are self closing | hackvertor | 7/16/2024 | XSS | 0 |
| Tags that HTML encode it's contents | hackvertor | 7/16/2024 | XSS | 0 |
| JavaScript Scheme starting with http | BinaryScary | 7/16/2024 | JS | 1 |
| React DOM src | IDKdir | 7/15/2024 | JS | 0 |
5 5 | Characters allowed before CSS selectors | hackvertor | 7/15/2024 | XSS | 0 |