Whoops kinda think we had a misunderstanding on the post.
I have downloaded the latest build (as of today) and you cheeky monkeys

have updated some of the code so html is no longer allowed. Last weeks version (Sept 3) did not have these changes in them.
So yes, as far as the version I downloaded last week html was allowed in those fields and additional code has been added to showproduct.php, reviews.php, and editproduct.php to prevent this.
(thats the stick out tongue smilie since my wife is none to thrilled with me spending the last two hours on the computer comparing files----why aren't you doing laundry she says)