the first result I see currently: https://github.com/matsprehn/122B/blob/1d54d2a72f25a23d63ff7...
also spotted this, which looks pretty harmless: https://github.com/cameroni2003/picgrid/blob/0b3becda1f250ef...
a lot others look similar, plus it depends on context...
I can definitely see the issue if the server saves the unfiltered input and tries to print that out for other uses, but it seems to me that outputting a raw $_GET variable will only go to the requester and therefore could only run unfiltered code on that requesters machine.
EDIT: Answering my own question:
This is a security hole because the unsafe JavaScript is stored in the URL for the page (it is a GET parameter). This bad URL could then be sent as a link in a spam email or similar. Victims clicking on the link would then see a page that comes from the legitimate source, but is running unsafe code compromising that user's session. This sort of attack relies on the attacker distributing the link with the bad code as a URL parameter, and is not a vulnerability that a user could encounter when just visiting that site as I had first assumed.
This (http://web.math.jjay.cuny.edu/fcm791/web2.0_Vulnerabilities....) is a pretty good paper (jump to page 7) if you are interested.