Sorry but you still have not identified or demonstrated any specific vulnerability, I have no response for this.
I know what cross site scripting is, but you have not shown me any specific xss vulnerability.
You need to point out exactly what javascript fragment you think is vulnerable and explain how it could be exploited, that is how an attacker could add their own script.
If you really understand the problem or if a problem really exists then you should be able to point to it and tell me what is wrong and how it could be exploited as well as how it could be fixed.
Telling me that some tool gives you a warning doesn't help me or convince me there is a problem.