. [normal link](javascript) .
. Should not allow some protocols in links and images . [xss link](javascript:alert(1)) [xss link](JAVASCRIPT:alert(1)) [xss link](vbscript:alert(1)) [xss link](VBSCRIPT:alert(1)) [xss link](file:///123) .[xss link](javascript:alert(1))
[xss link](JAVASCRIPT:alert(1))
[xss link](vbscript:alert(1))
[xss link](VBSCRIPT:alert(1))
[xss link](file:///123)
. . [xss link]("><script>alert("xss")</script>) . . . [xss link]([xss link](<javascript:alert(1)>)
. . [xss link](javascript:alert(1)) .[xss link](javascript:alert(1))
. Image parser use the same code base. . ![xss link](javascript:alert(1)) .![xss link](javascript:alert(1))
. Autolinks .<javascript:alert(1)>
<javascript:alert(1)>
. Linkifier . javascript:alert(1) javascript:alert(1) .javascript:alert(1)
javascript:alert(1)
.