There is an open foundation out there called OWASP that helps you with this.
To answer your question Are there any attacks....; Yes!
There are tons of documentation there, and there are libraries you can use to correctly escape all XSS code.
Read the XSS prevention sheet.