Anytime is possible for the data that returns to be interpolated by the client, you could have xss or related attack.
Client side rendering does help but mistakes are still regularly made. Sometimes by the app dev, sometimes by the framework dev.
You could probably go to an extreme and return all of your application data as sprites.