Modern Web Browsers mask this issue - but on older browsers or curl - one could inject javascript into the generated HTML. https://thisisnotfound.com/hello/<script>alert(1);</script> 