The Community updates on Homepage can be configured through Special:CommunityConfiguration to define the announcement the module should contain. This input is vulnerable to a XSS attack:
As of now, this is deployed to Beta Cluster only. Even if it was deployed to users, this would be only exploitable by administrators.