The data parameter of the /settings/api/router endpoint in Opsview Monitor prior to 5.3.1 and 5.4.x prior to 5.4.2 is vulnerable to Cross-Site Scripting.
opsview opsview