[#6889] use .text() instead of .html() to avoid html insertion of end-user input
1 file changed