Test your XSS payloads against intentionally vulnerable pages. Everything runs in a sandboxed iframe — no network access, fully isolated.
Input reflected directly into HTML body, no filtering.
Solved: 0/7