Description

ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to the exec() function. NOTE: this is disputed by the Supplier because there is no unsanitized user input to web/views/image.php.

INFO

Published Date :

2026-02-18T00:00:00.000Z

Last Modified :

2026-03-11T03:08:51.892Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-65791 vulnerability.

Vendors Products
Zoneminder
  • Zoneminder
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-65791.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact