Letting your users write HTML/CSS (or not escaping input) is a bad idea to begin with.
Letting your users write HTML/CSS (or not escaping input) is a bad idea to begin with.
It is never a good idea to accept HTML from a client, attempt to clean it up, and then pass it directly into the DOM of a server-generated page.
Although I respect the site's aim for completeness, the whole site could be shortened to one example of each issue. One example of "on..." attributes, one example of "javascript:" URLs, and so on. I don't see the value of the second, third, yet-another "on..." example. This is just hiding the deeper issues in a mess of seemingly clever examples.
Regarding the blacklist proposal, I really hope that nobody is seriously using those for HTML! One typo, one forgotten entry, or one new browser feature, and the blacklist's security drops to zero.
It's just a pity the good content is so watered down with dozens of obvious "you should sanitised user input" examples and variations of the same attacks.