in reply to Re: CGI to Dancer popup_menu
in thread CGI to Dancer popup_menu

A good habit for Template code is escape all template vars. That way DB/User-input strings can be plain/arbitrary without risk of XSS attacks.

E.g.: <% name | html %>