Plenty of frameworks have cross-site scripting protection ...

Plenty of frameworks have cross-site scripting protection but fail to protect the "logging out" route, which can be abused in its own ways. Odd.