Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ZoneMinder — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting ZoneMinder. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ZoneMinder serves as an open-source video surveillance solution for monitoring security cameras and managing video analytics. Historically, the application has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, contributing to its 18 recorded CVEs. Notable security characteristics include its PHP-based architecture and web interface, which have been frequent targets for exploitation. While no major public security incidents have been widely documented, the consistent discovery of vulnerabilities in its authentication and session management components highlights ongoing security challenges that require diligent patching and hardening in production environments.

Found 20 results / 20 Clear Filters
Top products by ZoneMinder: zoneminder
CVE ID Title CVSS Severity Published
CVE-2026-76060 OS Command Injection in PayRange API — Zoneminder CWE-78 8.8 High 2026-08-27
CVE-2026-72556 ZoneMinder ZoneMinder - Remote Code Execution — ZoneMinder CWE-78 8.8 High 2026-08-11
CVE-2026-27470 ZoneMinder: Second-Order SQL Injection in `getNearEvents()` via Stored Event Name and Cause Fields — zoneminder CWE-89 8.8 High 2026-02-21
CVE-2024-51482 Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64 — zoneminder CWE-89 10.0 Critical 2024-10-31
CVE-2024-43360 ZoneMinder Time-based SQL Injection — zoneminder CWE-89 9.8 Critical 2024-08-12
CVE-2024-43359 XSS vulnerabilities in montagereview — zoneminder CWE-79 - - 2024-08-12
CVE-2024-43358 XSS vulnerability in filter view — zoneminder CWE-79 6.1 Medium 2024-08-12
CVE-2023-41884 ZoneMinder Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in watch.php — zoneminder CWE-89 7.1 High 2024-08-12
CVE-2023-26039 ZoneMinder vulnerable to OS Command injection in daemonControl() API — zoneminder CWE-78 7.1 High 2023-02-25
CVE-2023-26038 ZoneMinder contains Local File Inclusion vulnerability via `web/ajax/modal.php` — zoneminder CWE-426 5.4 Medium 2023-02-25
CVE-2023-26037 ZoneMinder contains SQL Injection via report_event_audit — zoneminder CWE-89 8.9 High 2023-02-25
CVE-2023-26036 ZoneMinder contains Local File Inclusion vulnerability — zoneminder CWE-426 8.1 High 2023-02-25
CVE-2023-26035 ZoneMinder vulnerable to Missing Authorization — zoneminder CWE-862 7.2 High 2023-02-25
CVE-2023-26034 ZoneMinder SQL Injection — zoneminder CWE-89 9.6 Critical 2023-02-25
CVE-2023-26032 ZoneMinder contains SQL injection via malicious Jason Web Token — zoneminder CWE-89 8.9 High 2023-02-25
CVE-2023-25825 ZoneMinder contains Cross-site Scripting via log viewing — zoneminder CWE-79 7.7 High 2023-02-25
CVE-2022-39285 Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder — zoneminder CWE-79 7.6 High 2022-10-07
CVE-2022-39291 Denial of service through logs in zoneminder — zoneminder CWE-20 5.4 Medium 2022-10-07
CVE-2022-39290 CSRF key bypass using HTTP methods in zoneminder — zoneminder CWE-287 8.0 High 2022-10-07
CVE-2022-39289 Database log access in ZoneMinder — zoneminder CWE-200 9.1 Critical 2022-10-07

This page lists every published CVE security advisory associated with ZoneMinder. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.