I hope you would close this ticket. I didn't mark the payloads as code in the visual editor in SourceForge, due to which they got executed. I have created a new ticket with the issue mentioned in a proper way. Thanks, Binit Ghimire
Stored Cross-site Scripting (XSS) vulnerability in Vim Online
Stored Cross-site Scripting (XSS) vulnerability in Vim Online