That's true, but not what I was thinking of. Even big websites of some repute (like The Economist) are in the habit of letting a multitude of external agents run unrestricted JavaScript on their pages. As in this case, that power can be used to distribute exploits.