TL;DR: entity labels (editable by anyone) included directly as HTML on query.wikidata.org (not CORS-whitelisted)
The Wikidata Query Service UI (wikidata/query/gui in Gerrit) directly includes entity labels as HTML in the tooltip when hovering over an entity ID.
$( '<div class="panel-body">' ).html( text ).css( 'padding', '10px' ) )
To reproduce, open [SELECT (wd:Q43981055 AS ?x) {}](https://query.wikidata.org/#SELECT%20%28wd%3AQ43981055%20AS%20%3Fx%29%20%7B%7D) or a similar query, then hover your mouse over the item ID. The label of the item (β<script>alert("!Mediengruppe Bitnik");</script>β β yes, thatβs the actual title of a book) will be injected as HTML into the popup. Users can add almost arbitrary other HTML to the labels of other entities (subject to a limit of, I believe, some 500 characters), though of course this will show up in the history of that item, in recent changes, etc.