. [normal link](javascript) .
. Should not allow some protocols in links and images . [xss link](javascript:alert(1)) .[xss link](javascript:alert(1))
. . [xss link](JAVASCRIPT:alert(1)) .[xss link](JAVASCRIPT:alert(1))
. . [xss link](vbscript:alert(1)) .[xss link](vbscript:alert(1))
. . [xss link](VBSCRIPT:alert(1)) .[xss link](VBSCRIPT:alert(1))
. . [xss link](file:///123) .[xss link](file:///123)
. . [xss link]("><script>alert("xss")</script>) . . Image parser use the same code base. . ![xss link](javascript:alert(1)) .![xss link](javascript:alert(1))
.