In a JWT this is simple, the signature checks the entire sig and data sections. In XML signatures it checks whatever it says it checks, a list of URIs, which may also be transformed.
So it is possible to have an XML signature that points to an element that does not include some important piece of data.