Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Traccar — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Traccar, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the Traccar open-source GPS tracking server, focusing on specific weakness types identified in its release history. The collection spans the entire maintenance period of the product, compiling advisories that address issues such as authentication flaws, input validation gaps, and server-side logic errors. Readers can use this resource to track the vendor’s advisory patterns, understand the prevalence of particular weakness classes within the ecosystem, and review the full vulnerability history associated with this product. The data is presented neutrally to support risk assessment and remediation planning without promotional language.

Vendor: Traccar

CVE ID Title CVSS Severity Published
CVE-2026-52852 Traccar: Uncontrolled Infinite Loop DoS via Group Parent Cycle CWE-674 6.5 Medium 2026-09-17
CVE-2026-52851 Traccar: Authenticated Blind SQL Injection in DELETE /api/permissions CWE-89 7.1 High 2026-09-17
CVE-2026-44314 Traccar: Missing edit authorization on device image upload allows read-only users to write files CWE-863 - - 2026-05-26
CVE-2026-27694 traccar allows stored HTML injection in notification emails CWE-79 5.4 Medium 2026-05-05
CVE-2026-27693 traccar allows XML injection in KML and GPX exports CWE-91 5.4 Medium 2026-05-05
CVE-2026-27644 traccar allows CSV formula injection via exported position data CWE-1236 6.5 Medium 2026-05-05
CVE-2026-25649 Traccar Vulnerable to Authorization Code Theft via Open Redirect in OIDC Provider Endpoints CWE-352 7.3 High 2026-02-23
CVE-2026-25648 Traccar Vulnerable to Stored Cross-Site Scripting (XSS) via Malicious SVG File Upload CWE-79 8.7 High 2026-02-23
CVE-2026-23521 Traccar vulnerable to Path Traversal and External Control of File Name or Path CWE-22 6.5 Medium 2026-02-23
CVE-2025-68930 Traccar Missing Origin Validation in WebSockets CWE-1385 7.1 High 2026-02-23
CVE-2025-61666 Traccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config File CWE-22 9.1AI Critical AI 2025-10-02
CVE-2024-31214 Traccar's unrestricted file upload vulnerability in device image upload could lead to remote code execution CWE-434 9.7 Critical 2024-04-10
CVE-2024-24809 Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type CWE-27 8.5 High 2024-04-10
CVE-2023-50729 An unrestricted file upload vulnerability in traccar leads to RCE CWE-434 8.5 High 2024-01-15
CVE-2021-21292 Unquoted Windows binary path in Traccar CWE-428 5.5 Medium 2021-02-02
CVE-2020-5246 LDAP injection vulnerability in Traccar GPS Tracking System CWE-90 7.7 High 2020-07-14

All 16 known CVE vulnerabilities affecting Traccar with full Chinese analysis, references, and POCs where available.