You might also want to think about some things that are not likely to provide xss, but would cause visual problems. Eg <img src="" width="10000000" height="20000000"> or excessively large/small fonts.
regards
David Cameron
nOw.b2b
dcameron@itis-now.com