HTMLy version 2.9.9 suffers from a persistent cross site scripting vulnerability that can lead to account takeover.