Zoneminder is an open-source video surveillance and monitoring platform that, despite a narrow product scope, occupies a prominent position in the vulnerability landscape due to its widespread deployment in security infrastructure and the internet-accessible nature of many installations. Vulnerabilities affecting the platform skew toward serious outcomes, with a meaningful share reaching critical severity and a moderate tendency to acquire public exploit code, reflecting both the inherent attack surface of web-facing surveillance systems and the durable patterns in the codebase. The recurring weakness classes—including cross-site scripting, SQL injection, cross-site request forgery, sensitive information exposure, and code injection—are characteristic of web-application architectures with legacy input-handling and access-control patterns, and they concentrate entirely within the single Zoneminder product. Defenders should treat this vendor's advisories as high-priority for any internet-exposed or network-critical surveillance deployments, and should inventory instances carefully since remediation timelines may vary; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zoneminder over time
Signals from CVEs in this vendor scope (85 CVEs).
85 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26035CRITICAL ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vuln | Feb 25, 2023 | 9.8 | 87 | NO | YES |
CVE-2022-29806CRITICAL ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability. | Apr 26, 2022 | 9.8 | 77 | NO | YES |
CVE-2013-0232HIGH includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState par | Mar 20, 2013 | 7.5 | 65 | NO | YES |
CVE-2024-43360CRITICAL ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in | Aug 12, 2024 | 9.8 | 43 | NO | YES |
CVE-2022-39290MEDIUM ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by modifying the request supplied to | Oct 7, 2022 | 6.5 | 35 | NO | YES |
CVE-2018-1000832CRITICAL ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote | Dec 20, 2018 | 9.8 | 33 | NO | NO |
CVE-2022-39291MEDIUM ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a vulnerability which allows users with "View" syst | Oct 7, 2022 | 5.4 | 31 | NO | YES |
CVE-2022-39285MEDIUM ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerability (XSS) by backing out of th | Oct 7, 2022 | 5.4 | 31 | NO | YES |
CVE-2018-1000833CRITICAL ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote | Dec 20, 2018 | 9.8 | 31 | NO | NO |
CVE-2026-27470HIGH ZoneMinder is a free, open source closed-circuit television software application. In versions 1.36.37 and below and 1.37.61 through 1.38.0, there is a second-order SQL Injection vu | Feb 21, 2026 | 8.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (85 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zoneminder.
Media articles that mention a CVE ID that affects a product developed by Zoneminder — matched by CVE ID, not by vendor name.