onerror
partically fixed, but still available on editor...
onerror
partically fixed, but
still availableon editor... Fixed #1251
{onerror="alert('xss2')"}
script
// not hit<script>alert('xss3')</script>
<script>alert('xss3')</script>