CVE-2024-43360: Zoneminder

Critical severity, CVSS 9.8. EPSS: 6.2% chance of exploitation in the next 30 days.

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.

Affected products

  • Zoneminder Zoneminder: before 1.36.34 (fixed in 1.36.34); from 1.37.00, before 1.37.61 (fixed in 1.37.61)

Published 2024-08-12. Last modified 2026-06-17.