Check if you get something like [1] in the error.log when you save the dialog. If, yes, Tag is removed by the xss protection framework.Cross-site scripting (XSS) allows attackers to inject code into web pages viewed by other users. This security vulnerability can be exploited by malicious web users ...