PAYLOAD Visible but escaped PAYLOAD We close the tag so XHTML validation still succed :) but recent browsers will ignore it. In dubt remove the closing tag. PAYLOAD Original page contents after the first XSS injection.