regarding "htmlspecialchars" for XXS attack

We have noticed "htmlspecialchars" filters are implemented in Sugar10. Now Gradually increased "htmlspecialchars" filters are now being implemented in some more fields in Sugar11. Is there any specific reason?

And Which SugarCRM version the XXS attack filter condition are started?