Don't use this for anything where you don't want cross-site-scripting vulnerabilities...
Moreover you wouldn't use this for anything where you aren't in control of where people get the links from, because as soon as someone else starts sharing it they can of course edit it too.
Have a look at https://fiddle.jshell.net/pvcL4mjh/1/show/light/
Would you call that XSS / did I just steal JSFiddle's trustworthiness?