grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')