Ported XSS vulnerability fixes from stable branch

Merge request reports

Loading