Currently is someone is able to hack into one your of moderator accounts they could use it to launch a XSS assack since they could select the option to use HTML in announcements.
To fix this open modcp/announcement.php
Change
print_yes_no_row($vbphrase['allow_html']...