How are these getting drawn at all? Likely you need to be sure that user input is correctly encoded - this should be automatic in GXT 3 (and this is the GXT 3 forum), though requires some effort in GXT 2.
EditorGrid only exists in GXT 2 (the concept is slightly different in 3), so I assume you are talking about that. The easiest way is to set up a GridCellRenderer for the column that htmlencodes the strings passed in so no html is rendered. Consider the com.google.gwt.safehtml.shared.SafeHtmlUtils.htmlEscape(String) function for this purpose.
If you want to selectively process html tags, this isn't something GWT or GXT really provide support for, as there are many ways to render arbitrary content (use of img tag, iframe tag, onerror attribute, background-image css, to name only a few).