A new XSS WAF bypass technique has been discovered using invisible separators before or after the function name. The payload <img/src/onerror=alert&#xFEFF;(1337)><svg/onload=&nbsp;alert&#65279;(2)> can be used to bypass XSS protection. Security researchers recommend WAF vendors to update their protection mechanisms to mitigate this bypass.
