XSS

DOM Cross-Site Scripting

Portswigger DOM XSS in `document.write` sink using source `location.search` inside a select element

Reflected XSS into attribute with angle brackets HTML-encoded

Reflected XSS into attribute with angle brackets HTML-encoded

Reflected XSS with SVG Markup

Reflected XSS with some SVG markup allowed

Stored Cross-Site Scripting

Stored XSS into anchor 'href' attribute with double quotes HTML-encoded