https://en.wikipedia.org/w/thumb.php outputs a fairly long interface message (customised by enwiki admins) that looks like it is intended for Special:BadTitle. It outputs this, already confusing message, as raw html instead of text or wikitext.
Right now this is causing the browser to parse <code> and <nowiki>. It could trivially include <script> as well.