The codebase is lacking HTML entity and URI escaping throughout. Should add that whenever the data to output comes from a variable.