Try to inject a script that displays an alert (e.g., <script>alert('XSS')</script>).
<script>alert('XSS')</script>
Cross-Site Scripting (XSS) allows attackers to inject malicious JavaScript into web apps.
Try something like: <script>alert('XSS')</script>
DOMPurify
OWASP XSS Guide