Direct PrintWriter Output Without Encoding
Writing user input directly to HttpServletResponse PrintWriter without HTML encoding allows script injection.
Preview example – JAVA
// Vulnerable
String name = request.getParameter("name");
out.println("<h1>Welcome " + name + "!</h1>");