For silly reasons I ended up finding this slightly worrying bug in the code for this discussion site... Click on the textarea below: a javascript alert box should pop up. I have not tried, but this seems like a possible way to have code executed in people's browsers...
This is some random text
Anton Geraschenko
Also, it appears that this keeps the input field from appearing (so I can only leave a comment by editing this entry). Also, all this text doesn't appear once I save this edit. This should definitely not happen.
]]>