Cross-Site Scripting (XSS) vulnerability allows attackers to inject malicious scripts into Web sites, which can be executed with the users’ privilege.
Yes
Anywhere users' input is placed as output
Self-XSS is out of scope of this identification. Also, a case that we consider to have no impact is not identified as a vulnerability.