Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not directly contain JavaScript), because document.currentScript lookup can be shadowed by attacker-injected HTML elements.
https://gist.github.com/jackfromeast/31d56f1ad17673aabb6ab541e65a5534