The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.