Validate translation string values server-side with NoHTML() and MaxLen(2000) to reject HTML in the translations JSON blob. On the client side, escape user-provided template text before innerHTML injection in banner_description and placeholder_text paths. Signed-off-by: Émile Ré <emile@getprobo.com>