diff --git a/html/poketube.ejs b/html/poketube.ejs index 1ef47051..97db4c6f 100644 --- a/html/poketube.ejs +++ b/html/poketube.ejs @@ -1604,7 +1604,7 @@ WIP! <% } %>

- <%- x.content %>

+ <%- escapeHtml(x.content) %>

<% if (x.like_count === 0) { %> | <% } else { %> <%= x.like_count %> |