In any case, I think XXX should be dropped in favor of prefixes with some semantic meaning.
I use XXX when there's no obvious tag. Some things require attention or consideration at some indeterminate point in the future, but aren't bugs or hacks, and might not necessarily even need to be changed. They're just... a big fat question mark that you or somebody else might want to circle back around to.
Every programmer knows that naming things can be a tremendous tarpit. The only thing more tedious than choosing the best name for something is choosing a subtly misleading name which subsequently leads you or someone else on a wild good chase or possibly to fixing things (and accidentally breaking things) that never really needed to be fixed as long as the situation didn't change.
XXX is just the right convention precisely because it's so nebulous. NOTE doesn't work because something marked XXX isn't just locally descriptive, it's also a global marker that deserves to standout. WARNING doesn't work because that signals danger and hints that you may have done something suspect. But XXX doesn't necessarily mean code is suspect, it can be that it _might_ be suspect or that it _might_ be unnecessarily complex. ATTN is maybe the closest fit, but 1) isn't sufficiently loud and 2) lost out to XXX anyhow as a convention.
IME XXX is usually either 1) something that deserves reconsideration, and here's why ..., or 2) I'm too busy writing correct code to worry about the best description here, but here's a marker and possibly a sketch of a description for your future benefit.
Other than NOTE, I use XXX far more often than BUG or TODO. Committing a BUG comment is, I think, just poor discipline. If you know there's a bug, fix it or disable it.[1] I rarely use TODO inside code, but rather usually only in header files. That is, I use TODO to mark planned extension points. Inside implementation code I personally find TODO to be not much better than BUG, though reasonable people can certainly disagree on that point.
[1] I understand that sometimes neither fixing nor disabling is a realistic short-term option, especially in the corporate world. That doesn't make it any more excusable, though, especially if its your bug. And if you can actually get the BUG comment committed upstream one must wonder exactly how difficult it would have been to get an actual fix or mitigation upstream.