Well, I have continued my evaluation of the loader's source. I'm not finished and I won't, but if you want some good piece of advice, DON'T load any XML file that comes from an untrusted source using the Crystal Space XML plugins (be it tinyXML or the other one I forgot the name of).
Of course, feel free to inform us about the issues you find.
Still, CS doesn't have concepts of "trust" - if such a thing is desired, it's really up to the application to check that a data source is legit.