Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6937085
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 27, 20262026-05-27T12:19:08+00:00 2026-05-27T12:19:08+00:00

For my users’ profiles, I am going to let them insert HTML code, which

  • 0

For my users’ profiles, I am going to let them insert HTML code, which will be displayed on their profile.

Is there any special tags I need to manually remove when they save their profile?

Besides the <script> tag, what else could be dangerous?

What else could be “dangerous”?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-27T12:19:08+00:00Added an answer on May 27, 2026 at 12:19 pm

    applet, embed, object, script and iframe should be avoided at all costs.

    a and img can be problematic as they allow linking to off-site resources. They can also contain javascript: urls

    Avoid letting users enter any head-tags into cotnent meant for the body. style, link, meta, title etc

    You also have to be careful of attributes. Don’t allow any attribute that begins with on, as they are javascript event bindings. You also want to check any URL attributes for javascript: and data: urls.

    EDITED TO ADD:

    Forms and their children are also probably something to avoid as they can be used to dupe users into entering information that gets harvested by some other site.

    I’d recommend using a whitelisting policy instead of blacklisting when it comes to tags and attributes, as it’s far easier to miss something with a blacklist. Also with HTML5 gaining traction there’s a whole host of new tags and attributes to watch out for.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Users will be filling a field in with numbers relating to their account. Unfortunately,
Users would select their date from 3 dropdowns (day, month, year). I will combine
Users love their spreadsheets. And they want to use them as input into systems,
Our users input data using html editors (ckeditor and aspxhtmleidtor) which is saved in
Users of my app will have the option to select their preferred first day
Users have one profile, and profiles belong to users. I'm trying to make a
Users have their timezones stored in ASP.NET profiles as strings. I want to use
Users on my site can add nodes of a custom type (let's call it
Users of the website need to able to store images in their area ,
Users table: user_id | avatar ---------------------------------- 1 | file-name.jpg 2 | friendly-ghost.jpg Profile views

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.