in reply to "Hardening" a web forum app

Be sure to set default_escape => 'html' in the HTML::Template constructor, it's the best you can do against XSS.