Please expand on the below article for XSS risks for an enterprise internal Jira instance
https://confluence.atlassian.com/jirakb/enable-html-tag-usage-in-jira-server-text-fields-771895067.html
Is there a general guidance on enterprises that choose to enable the feature