When XML is imported into a document, its attribute values are not correctly presented to the DOM. This can allow their values to bypass sanitization filters. If these values are used as document content, they may in some cases allow scripts to be inserted.
Opera Software has released Opera 9.26, where this issue has been fixed.
Thanks to Arnaud Le Blanc for reporting this issue to Opera Software.