diff --git a/app/code/Magento/Theme/Block/Adminhtml/System/Design/Theme/Edit/Tab/Css.php b/app/code/Magento/Theme/Block/Adminhtml/System/Design/Theme/Edit/Tab/Css.php index 5e3bb8774d246..d47832a7187db 100644 --- a/app/code/Magento/Theme/Block/Adminhtml/System/Design/Theme/Edit/Tab/Css.php +++ b/app/code/Magento/Theme/Block/Adminhtml/System/Design/Theme/Edit/Tab/Css.php @@ -193,7 +193,7 @@ protected function _addCustomCssFieldset() Storage::PARAM_THEME_ID => $this->_getCurrentTheme()->getId(), Storage::PARAM_CONTENT_TYPE => \Magento\Theme\Model\Wysiwyg\Storage::TYPE_IMAGE ] - ) . "', null, null,'" . $this->escapeJs( + ) . "', null, null,'" . $this->_escaper->escapeJs( __('Upload Images') ) . "');", ] @@ -220,7 +220,7 @@ protected function _addCustomCssFieldset() Storage::PARAM_THEME_ID => $this->_getCurrentTheme()->getId(), Storage::PARAM_CONTENT_TYPE => \Magento\Theme\Model\Wysiwyg\Storage::TYPE_FONT ] - ) . "', null, null,'" . $this->escapeJs( + ) . "', null, null,'" . $this->_escaper->escapeJs( __('Upload Fonts') ) . "');", ] diff --git a/app/code/Magento/Theme/Block/Html/Topmenu.php b/app/code/Magento/Theme/Block/Html/Topmenu.php index fd8aaa7708cf3..98243da91b848 100644 --- a/app/code/Magento/Theme/Block/Html/Topmenu.php +++ b/app/code/Magento/Theme/Block/Html/Topmenu.php @@ -246,7 +246,7 @@ protected function _getHtml( } $html .= '
  • _getRenderedMenuItemAttributes($child) . '>'; - $html .= '' . $this->escapeHtml( + $html .= '' . $this->_escaper->escapeHtml( $child->getName() ) . '' . $this->_addSubMenu( $child, diff --git a/app/code/Magento/Theme/view/adminhtml/templates/browser/content/files.phtml b/app/code/Magento/Theme/view/adminhtml/templates/browser/content/files.phtml index 6b350cd625445..5756f82edc403 100644 --- a/app/code/Magento/Theme/view/adminhtml/templates/browser/content/files.phtml +++ b/app/code/Magento/Theme/view/adminhtml/templates/browser/content/files.phtml @@ -4,21 +4,24 @@ * See COPYING.txt for license details. */ -/** @var $block \Magento\Theme\Block\Adminhtml\Wysiwyg\Files\Content\Files */ +/** + * @var $block \Magento\Theme\Block\Adminhtml\Wysiwyg\Files\Content\Files + * @var \Magento\Framework\Escaper $escaper + */ ?> getFilesCount() > 0) : ?> getFiles() as $file) : ?> -
    +

    - escapeHtml($file['text']) ?> + escapeHtml($file['text']) ?> - <?= $block->escapeHtmlAttr(__('thumbnail')) ?> + <?= $escaper->escapeHtmlAttr(__('thumbnail')) ?>

    - escapeHtml(__('We found no files.')) ?> + escapeHtml(__('We found no files.')) ?> diff --git a/app/code/Magento/Theme/view/adminhtml/templates/browser/content/uploader.phtml b/app/code/Magento/Theme/view/adminhtml/templates/browser/content/uploader.phtml index 66456ae403818..e5ae910876ed8 100644 --- a/app/code/Magento/Theme/view/adminhtml/templates/browser/content/uploader.phtml +++ b/app/code/Magento/Theme/view/adminhtml/templates/browser/content/uploader.phtml @@ -4,15 +4,18 @@ * See COPYING.txt for license details. */ -/** @var $block \Magento\Theme\Block\Adminhtml\Wysiwyg\Files\Content\Uploader */ +/** + * @var $block \Magento\Theme\Block\Adminhtml\Wysiwyg\Files\Content\Uploader + * @var \Magento\Framework\Escaper $escaper + */ /** @var \Magento\Framework\View\Helper\SecureHtmlRenderer $secureRenderer */ ?>
    - escapeHtml(__('Browse Files')) ?> - + escapeHtml(__('Browse Files')) ?> +