Zoneminder 1.28.1 updated the dbEscape method to add single quotes around variables.
Removing the extra single-quote from views/watch.php line 27 for example:
$sql = "select C.*, M.* from Monitors as M left join Controls as C on (M.ControlId = C.Id ) where M.Id = ".dbEscape($_REQUEST['mid']);
There are probably quite a few instances of this throughout the skin but it's worth every second to fix them for this great improvement to zoneminder.