i have a limited idea of what i am talking about
xml, sgml, svg and html are not designed for security primarily, but the most damage is going to come from javascript and non-text (jpegs, mpegs, swf animations, binary applications with malware on github)
the biggest insecurity is the Luser, followed by the browser software's design (Firefox loves WebRTC and used to love NPAPI plugins, Chrome loves Flash, both love JavaScript and compilation in the browser). Since imageboards are built to support less Js than mainstay Web 2.0+ adwhores, imageboards are more secure by default. Just watch your OpSec, bucko