Zoneminder
92 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Zoneminder, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
Zoneminder CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 2 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 2 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 2 |
| 2026-09 | 1 |
Severity
How the 92 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical17
- High24
- Medium49
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Zoneminder.
- CVE-2026-54258Cross-monitor event media authorization bypass in direct event media endpoints6.5
- CVE-2026-76060OS Command Injection in PayRange API8.8
- CVE-2026-72556ZoneMinder ZoneMinder - Remote Code Execution8.8
- CVE-2026-27470ZoneMinder: Second-Order SQL Injection in `getNearEvents()` via Stored Event Name and Cause Fields8.8
- CVE-2025-65791ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() function. NOTE: this is disputed by the Supplier ...9.8
- CVE-2024-51482Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.649.9
- CVE-2023-31493RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing...6.6
- CVE-2024-43360ZoneMinder Time-based SQL Injection9.8
- CVE-2024-43359XSS vulnerabilities in montagereview—
- CVE-2024-43358XSS vulnerability in filter view6.1
- CVE-2023-41884ZoneMinder Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in watch.php7.1
- CVE-2020-25730Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, and obtain sensitive information via PHP_SELF com...8.2
- CVE-2023-26039ZoneMinder vulnerable to OS Command injection in daemonControl() API7.1
- CVE-2023-26038ZoneMinder contains Local File Inclusion vulnerability via `web/ajax/modal.php`5.4
- CVE-2023-26037ZoneMinder contains SQL Injection via report_event_audit8.9
Product grouping is registry-driven, with AI assist and human review. How it works