is yii xss varnurable?

sorry my fault… if you create custom error controller with view add


CHtml::encode($error['message']);