Traccar

Traccar

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 17.09.2026 18:32:07
  • Zuletzt bearbeitet 24.09.2026 21:25:27

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a trips or stops report for a device in that hierarchy. ...

  • EPSS -
  • Veröffentlicht 17.09.2026 18:30:33
  • Zuletzt bearbeitet 30.09.2026 17:51:56

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlled JSON key. Permission(LinkedH...

  • EPSS 0.19%
  • Veröffentlicht 26.05.2026 16:02:15
  • Zuletzt bearbeitet 24.07.2026 11:10:00

Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and then immediately streams the uploaded body into media...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 05.05.2026 13:16:28
  • Zuletzt bearbeitet 08.05.2026 20:03:41

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geofence, and driver names into HTML email output without proper escaping...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 05.05.2026 13:16:28
  • Zuletzt bearbeitet 08.05.2026 20:04:19

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper escaping. An attacker with low privileges can creat...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 05.05.2026 13:16:27
  • Zuletzt bearbeitet 08.05.2026 20:04:39

Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can ...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 23.02.2026 21:19:10
  • Zuletzt bearbeitet 26.02.2026 16:25:24

Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by uploading malicious SVG files as device images. The...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 23.02.2026 21:19:09
  • Zuletzt bearbeitet 26.02.2026 16:27:57

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices can set a device `uniqueId` to an absolute path. When uploading a device image, Traccar us...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 23.02.2026 21:12:06
  • Zuletzt bearbeitet 26.02.2026 16:23:23

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization codes by exploiting an open redirect vulnerability in two OIDC-related endpoints. The `...

Exploit
  • EPSS 0.54%
  • Veröffentlicht 23.02.2026 20:44:29
  • Zuletzt bearbeitet 26.02.2026 16:30:45

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails to validate the `Origin` header during the WebSocke...