Open
Description
Is it possible to inject <script>alert('xss')</script>
via translation string or is there sanitization to prevent this? It's not a new issues but I suspect all translations may be vulnerable to attacks like this. Of course, given Crowdin's review process, something like this is unlikely to pass review, but it's good to have defense in depth.
Originally posted by @silverwind in #24397 (comment)