So can the XSS your 'senior' web dev with 3 years startup experience and no security training left in your website. It's good that we're exposing flaws in new tech, but let's not ignore the old flaws.
Never. Trust. User. Data.
Never. Trust. User. Data.