By default, Jira allows HTML in custom field descriptions and list item values. The configuration item that prevents this is in Jira Admin -> System -> Enable HTML in custom field descriptions and list item values, and is is by default.
This introduces scope for values to break the page in exciting ways - for example, adding <!-- break the rest of the page when the field is loaded. Actually, on Field Configuration and Custom Fields pages, this prevents the ability to edit to undo the breakage (aside from editing the database)
Some customers require this, but, we should encourage it's disablement. Disabling it by default would help.
Disable this option by default
... It will now be switched to OFF for new Jira installations and the upgraded ones that have never used it. ... We recommend that you keep this option disabled for security reasons.