The new Filter HTML code functionality in Rich Text Editor 8 allows you to accept HTML input from your users, filter it to make sure it contains only an allowed set of tags, attributes and values and then display it without leaving yourself open to XSS holes.
The possible options are:
Default Black list: div White list: embed No html Full html