2
#OOPS#o.
For all sort of security reasons, I think it's better for you to moderate the uploads. The best way to do it is to use a contact form with surch a formulaire module. This one allow you to fix the sizes and file types that users will send to you.
Then, you'll be able to upload files yourself in a secure directory (with no write access) to enable links in your xoops.
Of course, this solution need a bit more job, but it's the safer !
Concerning CBB upload capacity, I think it's a good thing (I activated it with my recent upgrade), but you shouldn't open it for everybody...
In all cases : think security !