Hello,
I’m looking over the RSS generation, and I see there a call to a function called “html” - in tpl/tplimpl/embedded/templates/_default/rss.xml, line 35. Is that an undocumented alias to htmlEscape?
I’m also preparing a patch to properly escape more of the content that can reach RSS files, but that should be another story.
Dorin