. [normal link](javascript) .

normal link

. Should not allow some protocols in links and images . [xss link](javascript:alert(1)) [xss link](JAVASCRIPT:alert(1)) [xss link](vbscript:alert(1)) [xss link](VBSCRIPT:alert(1)) [xss link](file:///123) .

[xss link](javascript:alert(1))

[xss link](JAVASCRIPT:alert(1))

[xss link](vbscript:alert(1))

[xss link](VBSCRIPT:alert(1))

[xss link](file:///123)

. . [xss link]("><script>alert("xss")</script>) .

xss link

. . [xss link]() .

[xss link](<javascript:alert(1)>)

. . [xss link](javascript:alert(1)) .

[xss link](javascript:alert(1))

. Image parser use the same code base. . ![xss link](javascript:alert(1)) .

![xss link](javascript:alert(1))

. Autolinks . .

<javascript:alert(1)>

<javascript:alert(1)>

. Linkifier . javascript:alert(1) javascript:alert(1) .

javascript:alert(1)

javascript:alert(1)

.