GIJOE  Gunnery Sergeant   Posts: 4110
Do you know XSS?

Allowing HTML means Allowing XSS.

Thus, Modules allowing WYSIWYG eidtor for everybody has XSS vulnerablity.

piCal supports bbcode.
bbcode is a secure way to decorate contents for everyone.

It's enough I believe.

And you should know my first priority is the SECURITY.
Have you installed Protector?
