[quote=@Mahz] Can't allow HTML/CSS without heavy pre-processing to enforce a whitelist of safe usage. Which is exactly what BBCode is. :lol [/quote] I really would recommend against implementing code for HTML. No matter how many holes you cover up, someone will be able to break it; that system is too vulnerable.