If you have a user with HTML code in the username, the history of e.g.
issues or user details included the unescaped HTML code.

A patch to fix this problem is attached.

I tested with a username ending with:
 <a href="">foo</a>
which generated a clickable link in the history.
