// build the HTML body
vt = velocityEngine.getTemplate(template.getHtmlBodyTemplateResourcePath());
// HTML-escape all content inserted
EventCartridge ec = new EventCartridge();
ec.addEventHandler(new EscapeHtmlReference());
ec.attachToContext(velocityContext);
writer.getBuffer().setLength(0);
vt.merge(velocityContext, writer);
emailerFactory.setHtmlBody(response, writer.toString());
}