Let's test something
Nice try, but there are many security measures already in place to prevent XSS attacks.

I want to build smth with your API, do you escape HTML in the posts provided by it? Though it shouldn't matter that much, cause I should be escaping it anyway. Plus the forum escapes it too, so it should be pretty safe to use the provided HTML to display posts. Still I would like to test it more, but I'm afraid to trigger some sort of forum's automatic response if I'll just paste a ton of XSS payloads here.