DFL-061-25

Reflected search output strips only literal <script> tags before using inner HTML.

Try /search?q=....