106
With XOOPS you (currently) cannot control which tags are displayed. If you enable HTML, ALL tags can be displayed. Much more serious things can be done to your site than just this simple annoying 'script' that this user did.
I would suggest turn OFF html for forum posts. Allow bb-code if you want users to have control over their text. BB-code is a relatively safe alternative. If you *did* only have bb code enabled, let us know...
For the news, you might *need* to enable html to achieve certain control... if that is the case, you should only give access to trusted 'editors' or 'moderators' for approving articles. Any time you give access to HTML you should only give access to trusted people.