https://events.drupal.org/dublin2016/sessions/cracking-drupal
One man's bug is another man's hack
$username = 'hacker">LOL <img alt="';
print '<a title="' . $username . '">Not funny</a>';
<a title="hacker">LOL<img alt="">Not funny</a>