PayPal is one of the places who really care about security.
But even they were vulnerable to XSS type of attacks using the search feature (see this article for details).
At the moment, I’m not sure if that’s more embarrassing or frightening. Sure, it’s shameful but when even those guys don’t get it right … who can?