Prevent iframe url injection

Question asked by BijKluit on Dec 25, 2017
A user can inject code in an url to our forum. The discussion board uses iframes and the following exposes a thread:!

Not knowing up front each possible endpoint url because of the dynamic nature or a forum, what is the best way to prevent these injections?