This has been fixed by Ralf by disallowing all the tags (except <br>),
so the issue can be closed.

Note however that my patch escapes all the tags first, and then restores
only the allowed ones, so it should be as safe as the committed fix.

(I also noticed a minor mistake in the comment of the patch -- <a> is
not allowed anymore.)
