@Suiseiseki images, CSS, documents, most web resources have processing flaws which allow for unsandboxed code execution.
iFrame policies can often be bypassed using srcdoc, postMessage and clickjacking exploits. They will be obsoleted (eg. by fencedframes which offer full JavaScript support).
With AI, JavaScript will be indispensable to discern humans and to respect GDPR & NATO policies on privacy and ecology. HTML-only webpages will become unfit for most purposes.
CC: @tennoseremel @lxo