Welcome to RatXSS - a single-topic lab for CWAP Module 03: Cross-Site Scripting. Twelve sinks, twelve different injection contexts. The skill being drilled is context-aware payload construction: the same string is dangerous in one place and harmless in the next.
Where the bugs live
Search - reflected contexts (body, attribute, JS string, href), a naive filter, a bracket-encoded attribute, and a weak-CSP page.