in reply to Template toolkit XSS

Shoudl I escape ALL data passed to Template toolkit or in certain cases ?

It depends on what you're doing

If you're including html which should be displayed, it makes no sense to escape it

If you're including some attribute values, they should be html escaped

So yeah, you should think about what the data is coming into the template , then the template should do something you want with it