Attack example:

<img src=x onerror=alert(1)>

<script>alert("I'm so BAD");</script >

Plz input: