Yup, missing validation.
In ManageNews.controller.php (admin directory):
array('text', 'xmlnews_maxlen', 'subtext' => $txt['xmlnews_maxlen_note'], 10),
array('text', 'xmlnews_limit', 'subtext' => $txt['xmlnews_limit_note'], 10),
array('int', 'xmlnews_maxlen', 'subtext' => $txt['xmlnews_maxlen_note'], 10),
array('int', 'xmlnews_limit', 'subtext' => $txt['xmlnews_limit_note'], 10),
Pushed here:
https://github.com/emanuele45/Dialogo/commit/a3a4b41207df9a3db6b373887634604e10e4bfda