HTML in documentation is not properly escaped, which is an injection issue. You can see this by [searching for textarea](http://hayoo.fh-wedel.de/?query=textarea).