ZLMediaKit is a narrowly scoped media server and streaming framework that, despite limited public disclosure volume, occupies a specialized role in real-time video transport and live-streaming infrastructure. The durable signal centers on the core product's web-interface and input-handling attack surface, with recurring weaknesses including path traversal, cross-site scripting, and out-of-bounds read conditions that reflect typical exposure patterns in streaming and protocol-parsing code.
The number and severity of CVEs published that impact products developed by Zlmediakit over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35203HIGH ZLMediaKit is a streaming media service framework. the VP9 RTP payload parser in ext-codec/VP9Rtp.cpp reads multiple fields from the RTP payload based on flag bits in the first byt | Apr 6, 2026 | 7.5 | 28 | NO | NO |
CVE-2022-37237HIGH An attacker can send malicious RTMP requests to make the ZLMediaKit server crash remotely. Affected version is below commit 7d8b212a3c3368bc2f6507cb74664fc419eb9327. | Aug 30, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-31861HIGH ZLMediaKit 4.0 is vulnerable to Directory Traversal. | May 25, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-39067MEDIUM Cross Site Scripting vulnerability in ZLMediaKiet v.4.0 and v.5.0 allows an attacker to execute arbitrary code via a crafted script to the URL. | Sep 11, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zlmediakit.
Media articles that mention a CVE ID that affects a product developed by Zlmediakit — matched by CVE ID, not by vendor name.