📦 Traccar

by Traccar

🔍 What is Traccar?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-7746

CRITICAL CVSS 9.8 Aug 13, 2024

CVE-2024-7746 is a critical authentication bypass vulnerability in Tananaev Solutions Traccar Server that allows attackers to access the administrator panel using default credentials. This affects all...

CVE-2024-31214

CRITICAL CVSS 9.6 Apr 10, 2024

Traccar GPS tracking system versions 5.1 through 5.12 contain an unrestricted file upload vulnerability in the device image upload API. Attackers can upload arbitrary files with controlled content, na...

CVE-2026-25649

HIGH CVSS 7.3 Feb 23, 2026

This vulnerability allows authenticated users in Traccar GPS tracking systems to steal OAuth 2.0 authorization codes via open redirect in OIDC endpoints. Attackers can redirect these codes to maliciou...

CVE-2026-25648

HIGH CVSS 8.7 Feb 23, 2026

Authenticated users in Traccar GPS tracking system can upload malicious SVG files containing JavaScript, which executes in other users' browsers when they view the image. This cross-site scripting (XS...

CVE-2025-68930

HIGH CVSS 7.1 Feb 23, 2026

This CVE describes a Cross-Site WebSocket Hijacking vulnerability in Traccar GPS tracking system versions up to 6.11.1. Attackers can bypass Same Origin Policy to establish WebSocket connections using...

CVE-2023-50729

HIGH CVSS 8.4 Jan 15, 2024

CVE-2023-50729 is an unrestricted file upload vulnerability in Traccar GPS tracking systems that allows attackers to upload malicious files to arbitrary server locations. When exploited, this can lead...

CVE-2026-23521

MEDIUM CVSS 6.5 Feb 23, 2026

This vulnerability allows authenticated users in Traccar GPS tracking systems to write files outside the intended media directory by setting a device's uniqueId to an absolute path. Attackers could po...