Allowing (disabling) "Filter HTML for XSS" in the global settings/Security is not enough. At least for LimeSurvey 5.2.7, superadmin needs to additionally allow (disable) "Disable question script for XSS restricted user" -- although the manual explicitly says otherwise.
The manual might not reflect the added feature. There was a time where there was only a global XSS on/off setting.