simple and short modification to catalog/pollbooth.php to check the comment being posted and to stop it being entered into the database if it contains any html tags.

see attached install.txt file.
This is NOT a full package, just instructions to do this 30 second modification to pollboth.php - should work ok on any version.

More...