[quote=@Mahz]
Can't allow HTML/CSS without heavy pre-processing to enforce a whitelist of safe usage.
Which is exactly what BBCode is. :lol
[/quote]
I really would recommend against implementing code for HTML. No matter how many holes you cover up, someone will be able to break it; that system is too vulnerable.