Not just another XSS - @macabely

Use the ?content= parameter to render HTML.
It will be rendered under Content-Security-Policy: script-src 'none' :)

Hello, CTBB!