Bug Bounty Hint It's possible to execute XSS outside of DOM elements. Even if the DOM is disconnected (not inserted directly into the document), evaluated HTML with <img> tag can trigger the XSS payload.