It is difficult to implement a thorough sql injection/xss injection prevention on a site that doesn't cause false alarms. In a CMS the end user might want to use or that links to items from another site.
I recommend having all users install FireFox with NoScript ;-)