motioneye has 8 CVEs on record between 2022 and 2026. The busiest recent month was June 2026 with 5. The median CVSS is 7.2 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-22 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —
- Last 90 days
- 0 prev 5
Worst active — by depth score
CVE-2025-60787High· 7.2motionEye vulnerable to RCE via unsanitized motion config parameter55GHSA-qxvg-h7q2-hcxhCritical· 9.8motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)54GHSA-phv5-334h-mxcwCriticalmotionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal52CVE-2021-44255High· 7.2Unrestricted Upload of File with Dangerous Type in motionEye52CVE-2026-55488HighmotionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read41
motioneye vulnerabilities
CVEs affecting motioneye, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-55488HighmotionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read
motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read
GHSA-qxvg-h7q2-hcxhCritical· 9.8motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)
GHSA-phv5-334h-mxcwCriticalmotionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal
motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal
CVE-2026-31978Medium· 6.5motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint
motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint
CVE-2026-32315Medium· 5.5motionEye's World-Readable Configuration File Exposes Admin Password Hash
motionEye's World-Readable Configuration File Exposes Admin Password Hash
CVE-2025-60787High· 7.2PoCmotionEye vulnerable to RCE via unsanitized motion config parameter
motionEye vulnerable to RCE via unsanitized motion config parameter
CVE-2025-47782HighmotionEye vulnerable to RCE in add_camera Function Due to unsafe command execution
motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution
CVE-2021-44255High· 7.2PoCUnrestricted Upload of File with Dangerous Type in motionEye
Unrestricted Upload of File with Dangerous Type in motionEye