Screenshot 1 – DVWA Reflected XSS Page The Reflected XSS module in DVWA was opened in Browser 1. A JavaScript test payload was entered into the vulnerable input field while the application was running ...