Reflected XSS into a template literal with angle brackets, single, double quotes, backslash and backticks Unicode-escaped | Practitioner
(lab’s name is a bit of a handful)
As usual, let’s first insert our canary into the search form to see what’s the buzz:

While all our special characters are encoded thus no traditional payloads, notice that the page is trying to build the message dynamically using client-side JS. And backticks are used rather than single or double quotes, meaning we can probably inject JavaScript template literals within the message itself.
By inserting ${alert(1)}, we are greeted with this:
The payload works and an alert is triggered! Very interesting.