In the product attribute template code the attribute prompt is rendered as
This is a problem if there is any html in the prompt text. This should be &mvt:, not &mvte: I don't see a security issue as long as the attribute array is blanked out for every product before the array is populated. Is there a security issue? If not, please put it back to &mvt:
Code:
&mvte:attribute:prompt;