Portswigger DOM XSS in `document.write` sink using source `location.search` inside a select element
Reflected XSS into attribute with angle brackets HTML-encoded
Reflected XSS with some SVG markup allowed
Stored XSS into anchor 'href' attribute with double quotes HTML-encoded