Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Traccar — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Traccar, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerability data for the Traccar product, focusing on common weakness enumerations and associated tags maintained by the vendor. It compiles a comprehensive collection of known security flaws, including buffer overflows, cross-site scripting issues, and authorization bypasses, covering a historical timeline that spans from the software’s early releases through recent updates. Users can utilize this resource to track vendor advisories as they are issued, gain a deeper understanding of specific weakness classes within the context of Traccar’s architecture, and examine the complete vulnerability history of the product to assess long-term security trends. The information provided serves as a neutral reference point for security analysts, system administrators, and developers who need to evaluate the impact of these defects on their deployments. By organizing these findings in one accessible location, the page facilitates efficient risk assessment and informed decision-making regarding patching priorities and mitigation strategies. It does not imply endorsement or liability but rather aims to provide transparency into the security posture of the software over time. Readers are encouraged to consult official vendor documentation and additional security bulletins for detailed remediation steps and technical specifics related to each identified issue.

Vendor: Traccar

CVE ID Title CVSS Severity Published
CVE-2026-44314 Traccar: Missing edit authorization on device image upload allows read-only users to write files CWE-863 - - 2026-05-26
CVE-2026-27694 traccar allows stored HTML injection in notification emails CWE-79 5.4 Medium 2026-05-05
CVE-2026-27693 traccar allows XML injection in KML and GPX exports CWE-91 5.4 Medium 2026-05-05
CVE-2026-27644 traccar allows CSV formula injection via exported position data CWE-1236 6.5 Medium 2026-05-05
CVE-2026-25649 Traccar Vulnerable to Authorization Code Theft via Open Redirect in OIDC Provider Endpoints CWE-352 7.3 High 2026-02-23
CVE-2026-25648 Traccar Vulnerable to Stored Cross-Site Scripting (XSS) via Malicious SVG File Upload CWE-79 8.7 High 2026-02-23
CVE-2026-23521 Traccar vulnerable to Path Traversal and External Control of File Name or Path CWE-22 6.5 Medium 2026-02-23
CVE-2025-68930 Traccar Missing Origin Validation in WebSockets CWE-1385 7.1 High 2026-02-23
CVE-2025-61666 Traccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config File CWE-22 9.1AI Critical AI 2025-10-02
CVE-2024-31214 Traccar's unrestricted file upload vulnerability in device image upload could lead to remote code execution CWE-434 9.7 Critical 2024-04-10
CVE-2024-24809 Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type CWE-27 8.5 High 2024-04-10
CVE-2023-50729 An unrestricted file upload vulnerability in traccar leads to RCE CWE-434 8.5 High 2024-01-15
CVE-2021-21292 Unquoted Windows binary path in Traccar CWE-428 5.5 Medium 2021-02-02
CVE-2020-5246 LDAP injection vulnerability in Traccar GPS Tracking System CWE-90 7.7 High 2020-07-14

All 14 known CVE vulnerabilities affecting Traccar with full Chinese analysis, references, and POCs where available.