Vulnerabilities
77 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-27470 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vulnerability in the web/ajax/status.php file within the getNearEvents() function. Event field values (specifically Name and Cause) are stored safely via parameterized queries but are later retrieved and concatenated directly into SQL WHERE clauses without escaping. An authenticated user with Events edit and view permissions can exploit this to execute arbitrary SQL queries. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2025-65791 | ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() function. NOTE: this is disputed by the Supplier because there is no unsanitized user input to web/views/image.php. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2023-31493 | RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted pay RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system. NVD description · AI analysis pending | 6.6 | <1% |
| — | ||
| CVE-2024-43360 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61. NVD description · AI analysis pending | 9.8 group max | 6% | PoC |
| — | |
| CVE-2020-25730 | Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, and obtain s Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, escalate privileges, and obtain sensitive information via PHP_SELF component in classic/views/download.php. NVD description · AI analysis pending | 8.2 | <1% |
| — | ||
| CVE-2023-26035 | ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33. NVD description · AI analysis pending | 9.8 group max | 80% |
| — | ||
| CVE-2022-30768 +1 in the same advisory: …30769 | A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or n A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method. NVD description · AI analysis pending | 5.4 group max | <1% |
| — | ||
| CVE-2022-39289 | ZoneMinder is a free, open source Closed-circuit television software application. ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo upgrade as soon as possible. Users unable to upgrade should disable database logging. NVD description · AI analysis pending | 7.5 group max | <1% | PoC |
| — | |
| CVE-2022-29806 | ZoneMinder before 1.36.13 allows remote code execution via an invalid language. ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability. NVD description · AI analysis pending | 9.8 | 67% | PoC ×2 |
| — | |
| CVE-2020-25729 | ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php. ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php. NVD description · AI analysis pending | 6.1 | 1% |
| — | ||
| CVE-2019-13072 | Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who nav Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page. NVD description · AI analysis pending | 5.4 | <1% | PoC ×2 |
| — | |
| CVE-2019-8427 | daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters. daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2019-7346 | A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allo A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a "Try again" button, which allows resending the failed request, making the CSRF attack successful. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — |