Profile display name security hardening (Romarchive Team)

Blog

Profile display name security hardening

By Romarchive Team | 2026-08-29

As part of ongoing security maintenance, we fixed how user profile pages render the display name and page title. All user-supplied profile text is now properly HTML-escaped when displayed, and the profile input filter now also rejects angle-bracket characters. This prevents stored script injection through display names.

No action is required from users.

Back to Blog