You want to accept text input from users: comments on your forum, entries in your wiki, et cetera. You want the users to be able to add formatting to their text. If they are allowed to use the full spectrum of HTML in their input, you run the risk of XSS or just broken-looking pages. [...]





