Stored XSS via Sanitizer Bypass: Where Allowlists Break Down
Your HTML sanitizer has an allowlist. You trust it. But stored XSS still lands in production β because allowlists are only as good as their edge-case handling. Here's exactly where they fail and how to close the gaps.