CVE-2018-16147: Opsview

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.

Affected products

  • Opsview Opsview: before 5.3.1 (fixed in 5.3.1); from 5.4.0, before 5.4.2 (fixed in 5.4.2)

Published 2018-09-05. Last modified 2026-06-17.