The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor prior to 5.3.1 and 5.4.x prior to 5.4.2 is vulnerable to Cross-Site Scripting.
opsview opsview