Firefox is still vulnerable to XSS
maxwellito.tumblr.com
maxwellito.tumblr.com
There's a better solution though: CSP. Yes, it requires action from the site owners and is a bit of a pain to implement on an established website, but it's very effective at fighting both reflected and persistent XSS, and it can prevent other attacks too, such as content exfiltration using dangling markup injection.
Here is a URL to test : http://berghain.de/events/%22%20onmouseover=%22alert%28'NEIN...
Once on the page go on the 'onmouseover' text. the alert will appear only on Firefox. On other browsers, just check the console to see the Auditor blocking the attack.