Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zoneminder

First CVE: May 1, 2008Active for: 18 yearsTotal CVEs: 85
46.7
VTI Score
High

Zoneminder is an open-source video surveillance and monitoring platform that, despite a narrow product scope, occupies a prominent position in the vulnerability landscape due to its widespread deployment in security infrastructure and the internet-accessible nature of many installations. Vulnerabilities affecting the platform skew toward serious outcomes, with a meaningful share reaching critical severity and a moderate tendency to acquire public exploit code, reflecting both the inherent attack surface of web-facing surveillance systems and the durable patterns in the codebase. The recurring weakness classes—including cross-site scripting, SQL injection, cross-site request forgery, sensitive information exposure, and code injection—are characteristic of web-application architectures with legacy input-handling and access-control patterns, and they concentrate entirely within the single Zoneminder product. Defenders should treat this vendor's advisories as high-priority for any internet-exposed or network-critical surveillance deployments, and should inventory instances carefully since remediation timelines may vary; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
85
Total CVEs
More Total CVEs than 99% of tracked vendors
7.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zoneminder over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 1, 2008
18 years ago
Most Recent CVE
Feb 21, 2026
153 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (85 CVEs).

85 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-26035CRITICAL
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vuln
Feb 25, 20239.887NOYES
CVE-2022-29806CRITICAL
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.
Apr 26, 20229.877NOYES
CVE-2013-0232HIGH
includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState par
Mar 20, 20137.565NOYES
CVE-2024-43360CRITICAL
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in
Aug 12, 20249.843NOYES
CVE-2022-39290MEDIUM
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by modifying the request supplied to
Oct 7, 20226.535NOYES
CVE-2018-1000832CRITICAL
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote
Dec 20, 20189.833NONO
CVE-2022-39291MEDIUM
ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a vulnerability which allows users with "View" syst
Oct 7, 20225.431NOYES
CVE-2022-39285MEDIUM
ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerability (XSS) by backing out of th
Oct 7, 20225.431NOYES
CVE-2018-1000833CRITICAL
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote
Dec 20, 20189.831NONO
CVE-2026-27470HIGH
ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vu
Feb 21, 20268.830NONO
View all 85 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products85 CVEs
61%
20%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (2.4%)
Network75 (88.2%)
Unknown8 (9.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low75 (88.2%)
High2 (2.4%)
Unknown8 (9.4%)
User Interaction
None28 (32.9%)
Unknown8 (9.4%)
Required49 (57.6%)
Privileges Required
Low14 (16.5%)
High2 (2.4%)
None61 (71.8%)
Unknown8 (9.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (85 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.5% of CVEs· 98th percentile
Nuclei
2 CVEs
2.4% of CVEs· 95th percentile
ExploitDB
5 CVEs
5.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zoneminder.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zoneminder — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zoneminder's Products

View all 3 CNAs →

Top CWEs