Unfortunately yes. Potential XSS (though the phpBB parsing engine tries its best to prevent that), and various other problems can arise.ferrethouse2004 wrote: I implemented a mod to allow youtube videos but it didn't work. So I've enabled HTML on my forums and added embed, param, object as allowed tags. Is this a bad move?