There was a report on en.wp’s Administrator noticeboard/incidents of a user having a link to a pornographic website hidden in his custom signature. External links should not be allowed in the custom signature interface as this can lead to a vulnerability to phishing attacks or other general vandalism linking.
Link to ANI thread:
https://en.wikipedia.org/w/index.php?oldid=1290678644#User:Mifflefunt_is_NOTHERE
Link to related discussion:
https://en.wikipedia.org/wiki/Special:PermanentLink/1290697957#Phab_report_needed_for_signature_vulnerability