See "http://pciguru.wordpress.com/2013/06/30/developers-beware-st.... If you accept a CVC or CVC2, the requirements are much stricter, because an attacker who can get hold of a card number with the CVC/CVC2 can buy more expensive items.
Stripe works by having pages invoke their "stripe.js" within the host page. The risk of mixing payment processing input into a general site is that anything that can access the DOM can patch "stripe.js" and tap the credit card data. Since this page is very likely to be attacked, that's a big risk here.
The page uses several off-site Javascript files. Attacks through the CDN that distributes "bootstrap.js", for example, might work.
In 2015, payment card requirements are tightening up. Sites which use third party processors like Stripe will probably have to put credit card entry into an iframe which comes directly from the third party processor. This makes the attack surface smaller.