Yes, that's a perfectly valid question we ask ourselves regularly. I work in security at one of the companies named in this thread. We probably receive hundreds of XSS reports to our bug bounty every week to the point where most bug bounties won't pay out XSS unless you can demonstrate that it actually leads to something. Because it almost always doesn't.
Demonstrating a vulnerability requires demonstrating it's value. We will never build a perfectly secure system: risk management matters.