Home/Product/zoneminder
Product

zoneminder

86 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-27470
< 1.36.38
ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 throug
8.8HIGH
CVE-2025-65791
all versions
ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input direc
9.8CRITICAL
CVE-2023-31493
<= 1.36.33
RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder,
6.6MEDIUM
CVE-2024-43360
< 1.36.34
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injec
9.8CRITICAL
CVE-2024-43359
< 1.36.34
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerabil
NONE
CVE-2024-43358
< 1.36.34
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder has a cross-site scripting vulnerabil
6.1MEDIUM
CVE-2023-41884
< 1.36.34
ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few para
7.1HIGH
CVE-2020-25730
< 1.34.21
Cross Site Scripting (XSS) vulnerability in ZoneMinder before version 1.34.21, allows remote attackers execute arbitrary code, esc
8.2HIGH
CVE-2023-26039
< 1.36.33
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog camer
7.1HIGH
CVE-2023-26038
< 1.36.33
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog camer
5.4MEDIUM
CVE-2023-26037
< 1.36.33
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog camer
8.9HIGH
CVE-2023-26036
< 1.36.33
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog camer
8.1HIGH
CVE-2023-26035
< 1.36.33
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog camer
7.2HIGH
CVE-2023-26034
< 1.36.33
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog camer
9.6CRITICAL
CVE-2023-26032
< 1.36.33
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog camer
8.9HIGH
CVE-2023-25825
< 1.36.33
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog camer
7.7HIGH
CVE-2022-30769
<= 1.36.12
Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user.
4.6MEDIUM
CVE-2022-30768
all versions
A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the User
5.4MEDIUM
CVE-2022-39291
< 1.36.27
ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a
5.4MEDIUM
CVE-2022-39290
< 1.36.27
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can byp
8.0HIGH
CVE-2022-39289
<= 1.36.27
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes
9.1CRITICAL
CVE-2022-39285
< 1.36.27
ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site
7.6HIGH
CVE-2022-29806
< 1.36.13
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary
9.8CRITICAL
CVE-2020-25729
< 1.34.21
ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.
6.1MEDIUM
CVE-2019-13072
all versions
Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in t
5.4MEDIUM
CVE-2019-8429
< 1.32.3
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
9.8CRITICAL
CVE-2019-8428
< 1.32.3
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGro
9.8CRITICAL
CVE-2019-8427
< 1.32.3
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
9.8CRITICAL
CVE-2019-8426
< 1.32.3
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl
6.1MEDIUM
CVE-2019-8425
< 1.32.3
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
6.1MEDIUM
CVE-2019-8424
< 1.32.3
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
9.8CRITICAL
CVE-2019-8423
<= 1.32.3
ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.
9.8CRITICAL
CVE-2019-7352
<= 1.32.3
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'state' (aka Run State) (state.php) does
6.1MEDIUM
CVE-2019-7351
<= 1.32.3
Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which i
6.5MEDIUM
CVE-2019-7350
<= 1.32.3
Session fixation exists in ZoneMinder through 1.32.3, as an attacker can fixate his own session cookies to the next logged-in user
7.3HIGH
CVE-2019-7349
<= 1.32.3
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code
6.1MEDIUM
CVE-2019-7348
<= 1.32.3
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript c
6.1MEDIUM
CVE-2019-7347
<= 1.32.3
A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for an authent
7.5HIGH
CVE-2019-7346
<= 1.32.3
A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called displaying a
8.8HIGH
CVE-2019-7345
<= 1.32.3
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'options' (options.php) does no input va
4.8MEDIUM
CVE-2019-7344
<= 1.32.3
Reflected XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'filter' as
6.1MEDIUM
CVE-2019-7343
<= 1.32.3
Reflected - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript cod
6.1MEDIUM
CVE-2019-7342
<= 1.32.3
POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via
6.1MEDIUM
CVE-2019-7341
<= 1.32.3
Reflected - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript cod
6.1MEDIUM
CVE-2019-7340
<= 1.32.3
POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via
6.1MEDIUM
CVE-2019-7339
<= 1.32.3
POST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via
6.1MEDIUM
CVE-2019-7338
<= 1.32.3
Self - Stored XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'group'
6.1MEDIUM
CVE-2019-7337
<= 1.32.3
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 as the view 'events' (events.php) insecurely displays the
4.8MEDIUM
CVE-2019-7336
<= 1.32.3
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view _monitor_filters.php contains takes in i
6.1MEDIUM
CVE-2019-7335
<= 1.32.3
Self - Stored XSS exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in the view 'log' a
6.1MEDIUM
CVE-2019-7334
<= 1.32.3
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code
6.1MEDIUM
CVE-2019-7333
<= 1.32.3
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code
6.1MEDIUM
CVE-2019-7332
<= 1.32.3
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code
6.1MEDIUM
CVE-2019-7331
<= 1.32.3
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field named "signal
6.1MEDIUM
CVE-2019-7330
<= 1.32.3
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code
6.1MEDIUM
CVE-2019-7329
<= 1.32.3
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the form action on multiple views utilizes $_SERVER['
6.1MEDIUM
CVE-2019-7328
<= 1.32.3
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code
6.1MEDIUM
CVE-2019-7327
<= 1.32.3
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code
6.1MEDIUM
CVE-2019-7326
<= 1.32.3
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript c
6.1MEDIUM
CVE-2019-7325
<= 1.32.3
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/views insecure
6.1MEDIUM
CVE-2019-6992
<= 1.32.3
A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker to execute
6.1MEDIUM
CVE-2019-6991
<= 1.32.3
A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1
9.8CRITICAL
CVE-2019-6990
<= 1.32.3
A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML o
5.4MEDIUM
CVE-2019-6777
all versions
An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/index.php?vie
6.1MEDIUM
CVE-2018-1000833
<= 1.32.2
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of
9.8CRITICAL
CVE-2018-1000832
<= 1.32.2
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of
9.8CRITICAL
CVE-2017-7203
all versions
A Cross-Site Scripting (XSS) was discovered in ZoneMinder before 1.30.2. The vulnerability exists due to insufficient filtration o
6.1MEDIUM
CVE-2016-10206
<= 1.30.0
Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authenticatio
8.8HIGH
CVE-2016-10205
<= 1.30.0
Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMSESSID cook
7.3HIGH
CVE-2016-10204
<= 1.30.0
SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit
9.8CRITICAL
CVE-2016-10203
<= 1.30.0
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or
6.1MEDIUM
CVE-2016-10202
<= 1.30.0
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or
6.1MEDIUM
CVE-2016-10201
<= 1.30.0
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or
6.1MEDIUM
CVE-2017-5595
<= 1.30.0
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered
5.5MEDIUM
CVE-2017-5368
all versions
ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which a
8.8HIGH
CVE-2017-5367
all versions
Multiple reflected XSS vulnerabilities exist within form and link input parameters of ZoneMinder v1.30 and v1.29, an open-source C
6.1MEDIUM
CVE-2016-10140
all versions
Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMin
7.5HIGH
CVE-2013-0332
all versions
Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary files via
CVE-2013-0232
all versions
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary command
CVE-2008-6756
all versions
ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username
CVE-2008-6755
all versions
ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, wh
CVE-2008-3882
<= 1.23.3
Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary comman
CVE-2008-3881
<= 1.23.3
Multiple cross-site scripting (XSS) vulnerabilities in ZoneMinder 1.23.3 and earlier allow remote attackers to inject arbitrary we
CVE-2008-3880
<= 1.23.3
SQL injection vulnerability in zm_html_view_event.php in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrar
CVE-2008-1381
all versions
ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execu
CVE-2004-0227
all versions
Buffer overflow in the zms script in ZoneMinder before 1.19.2 may allow a remote attacker to execute arbitrary code via a long que
threatengine.sh