while noscript is awesome it doesnt mean you can turn your brain off while browsing:)
A site is on the default whitelist of the addon that can contain a malicious payload. Any site on the internet could therefor have a link to this payload. Granted, I'm not sure what sort of malicious JS payloads there are, other than crashing a browser, that doesn't involve some XSS.
NoScript isn't a comprehensive security/privacy suite. It's just a crucial component.