wrap pretty much all freemarker variables (i.e the data) in encodeHTML(data..). this...