Boofo, I did try multiple code boxes.
It might have been HTML in the code box. I saw HTML was actually parsing AS HTML

!
Everyone should upgrade to 1.2 ASAP!
Version 1.0 can be exploited if malicious users sent an iframe or javascript code in a pm.
This has been fixed in version 1.2... Also for those running 4.1.12 or above previews will now show in the user cp as well as the inbox itself.