Not sanitizing input, by either scrubbing out any <script> tags, or escaping those characterst to html entities.
"<script>" might be a legitimate input.
If you escape one step further you'll lose formatting or the message, so sanitisation is important too, it is reductive to say "always escape never sanitise".