zero.wikipedia.org has raw html enabled. However ZeroPortal allows parsing arbitrary wikitext from url GET parameters in the event the user has the zero-edit right. This is an XSS.
The potential attack scenario I see would be someone sends a phising email with a url like http://zero.wikimedia.org/wiki/Special:ZeroPortal?portal=ns:0}}%3Chtml%3E%3Cscript%3Ealert(1)%3C/script%3E%3C/html%3E to a zero-admin, and then uses that to take over their privileged account and do further evil.