XSS contournerait plus que

" onmouseover="alert('GOTCHA')"
Poor Piranha