XSS Attack [News topics]

It seems to insert a link in posts too. I typed the words “project file” and something inserted a link in my post afterwards. I had to manually remove it.