Tiki before 21.2 allows XSS because [s/»‘] is not properly considered in lib/core/TikiFilter/PreventXss.php.