Has the
img tag exploit been fixed for the Xenforo version?
How sure are you that there are not any other exploits?
And because for Xenforo you need to have a separate database for the shoutbox, if someone exploit the shoutbox, would they only have access to the shoutbox database not the Xenforo one?