Yes, I was about to say this - if you have a secure enough content security policy (and the browser in question supports it properly) it will be impossible for an attacker to execute their inserted Javascript (which to be able to do this anyway is also a security vulnerability).
But yes, the best plan is to have HTTPS everywhere, something that looks a lot closer than it once did! Thanks NSA!