This page includes a malicious SVG in the Open Graph og:image tag.
og:image
It also renders the SVG below directly via an <img> tag to demonstrate in-browser XSS if SVG isn't sanitized:
<img>