Severe CSRF to XSS bugs open the door to code execution and complete website compromise.
Source: Threadpost