Reflected XSS: The attack payload is included in a parameter when the victim follows a URL to the site.

Stored XSS: The attack payload is stored in the site itself and when anyone visits the page, regardless of the URL followed, the attack executes.

