Was reports that some missing HTML encoding could lead to XSS/javascript injection. Reviewable chunk of https://github.com/hestiacp/hestiacp/pull/5245 , which grew too large.