Traccar

Traccar

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 26.05.2026 16:02:15
  • Zuletzt bearbeitet 27.05.2026 14:02:55

Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and then immediately streams the uploaded body into media...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 05.05.2026 13:16:28
  • Zuletzt bearbeitet 08.05.2026 20:04:19

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper escaping. An attacker with low privileges can creat...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 05.05.2026 13:16:28
  • Zuletzt bearbeitet 08.05.2026 20:03:41

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geofence, and driver names into HTML email output without proper escaping...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 05.05.2026 13:16:27
  • Zuletzt bearbeitet 08.05.2026 20:04:39

Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can ...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 23.02.2026 21:19:10
  • Zuletzt bearbeitet 26.02.2026 16:25:24

Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by uploading malicious SVG files as device images. The...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 23.02.2026 21:19:09
  • Zuletzt bearbeitet 26.02.2026 16:27:57

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices can set a device `uniqueId` to an absolute path. When uploading a device image, Traccar us...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 23.02.2026 21:12:06
  • Zuletzt bearbeitet 26.02.2026 16:23:23

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization codes by exploiting an open redirect vulnerability in two OIDC-related endpoints. The `...

Exploit
  • EPSS 0.54%
  • Veröffentlicht 23.02.2026 20:44:29
  • Zuletzt bearbeitet 26.02.2026 16:30:45

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails to validate the `Origin` header during the WebSocke...

  • EPSS 1.21%
  • Veröffentlicht 02.10.2025 21:15:47
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and non default installs between versions 5.8 - 6.0 are vulnerable to unauthenticated local file inclusion attacks which can lead to le...

  • EPSS 0.53%
  • Veröffentlicht 13.08.2024 16:15:09
  • Zuletzt bearbeitet 22.08.2024 14:40:44

Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwise be prote...