You can use the options to set the output as text() rather than html(), e.g. $('div').magicpreview('mp_', { 'change': 'text' });
But yes, I should really add a flag to strip out any script elements :)
But yes, I should really add a flag to strip out any script elements :)
<table style="background-image:url(javascript:alert(1))"><tr><td>Hi</td></tr></table>
However, read debt's comment below. XSS is irrelevant here since "XSS" means cross-site scripting, i.e., ,managing to embed Javascript into pages someone ELSE sees. Only the client sees this, it doesn't get reproduced for anyone else.