I\'ve often wondered -- why use a whitelist as opposed to a blacklist when sanitizing HTML input?
How many sneaky HTML tricks are there to open XSS vulnerabilities?
Because other tags can break the layout of a page. Imagine what would happen if someone injects tag. tag is also dangerous.