Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

zoneminder — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in zoneminder, with AI-generated Chinese analysis, references, and POCs.

This page documents the vulnerability aggregation data for Zoneminder, a video management system, categorized under the weakness type of general software vulnerabilities. The content herein compiles a comprehensive collection of identified security issues, including remote code execution flaws, authentication bypasses, and information disclosure weaknesses, covering historical records from the initial public releases through recent major updates to ensure a complete audit trail of the product's security posture. By reviewing this curated dataset, users can effectively track vendor advisories and patch release notes to understand the context and severity of reported issues. Readers are also empowered to deepen their understanding of specific weakness classes within the context of video surveillance infrastructure, allowing for better risk assessment and mitigation strategies. Furthermore, the page serves as a historical reference for looking up a product's vulnerability timeline, enabling security professionals and administrators to identify patterns in recurring bugs or persistent architectural flaws that may have been addressed in later versions. This structured approach facilitates informed decision-making regarding system upgrades, configuration hardening, and the overall lifecycle management of Zoneminder deployments. Whether you are a system administrator responsible for maintaining the integrity of a surveillance network or a security researcher analyzing the threat landscape of open-source video management tools, this resource provides the necessary technical details and chronological context to evaluate the current security stance of the software.

Vendor: ZoneMinder

CVE IDTitleCVSSSeverityPublished
CVE-2026-72556 ZoneMinder ZoneMinder - Remote Code Execution CWE-78 8.8 High2026-08-11
CVE-2026-27470 ZoneMinder: Second-Order SQL Injection in `getNearEvents()` via Stored Event Name and Cause Fields CWE-89 8.8 High2026-02-21
CVE-2024-51482 Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64 CWE-89 10.0 Critical2024-10-31
CVE-2024-43360 ZoneMinder Time-based SQL Injection CWE-89 9.8 Critical2024-08-12
CVE-2024-43359 XSS vulnerabilities in montagereview CWE-79--2024-08-12
CVE-2024-43358 XSS vulnerability in filter view CWE-79 6.1 Medium2024-08-12
CVE-2023-41884 ZoneMinder Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in watch.php CWE-89 7.1 High2024-08-12
CVE-2023-26039 ZoneMinder vulnerable to OS Command injection in daemonControl() API CWE-78 7.1 High2023-02-25
CVE-2023-26038 ZoneMinder contains Local File Inclusion vulnerability via `web/ajax/modal.php` CWE-426 5.4 Medium2023-02-25
CVE-2023-26037 ZoneMinder contains SQL Injection via report_event_audit CWE-89 8.9 High2023-02-25
CVE-2023-26036 ZoneMinder contains Local File Inclusion vulnerability CWE-426 8.1 High2023-02-25
CVE-2023-26035 ZoneMinder vulnerable to Missing Authorization CWE-862 7.2 High2023-02-25
CVE-2023-26034 ZoneMinder SQL Injection CWE-89 9.6 Critical2023-02-25
CVE-2023-26032 ZoneMinder contains SQL injection via malicious Jason Web Token CWE-89 8.9 High2023-02-25
CVE-2023-25825 ZoneMinder contains Cross-site Scripting via log viewing CWE-79 7.7 High2023-02-25
CVE-2022-39285 Stored Cross-Site Scripting Vulnerability In File Parameter in zoneminder CWE-79 7.6 High2022-10-07
CVE-2022-39291 Denial of service through logs in zoneminder CWE-20 5.4 Medium2022-10-07
CVE-2022-39290 CSRF key bypass using HTTP methods in zoneminder CWE-287 8.0 High2022-10-07
CVE-2022-39289 Database log access in ZoneMinder CWE-200 9.1 Critical2022-10-07

All 19 known CVE vulnerabilities affecting zoneminder with full Chinese analysis, references, and POCs where available.