Traccar

Traccar

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 23.02.2026 21:19:10
  • Zuletzt bearbeitet 26.02.2026 16:25:24

Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by uploading malicious SVG files as device images. The...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 23.02.2026 21:19:09
  • Zuletzt bearbeitet 26.02.2026 16:27:57

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or edit devices can set a device `uniqueId` to an absolute path. When uploading a device image, Traccar us...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 23.02.2026 21:12:06
  • Zuletzt bearbeitet 26.02.2026 16:23:23

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization codes by exploiting an open redirect vulnerability in two OIDC-related endpoints. The `...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 23.02.2026 20:44:29
  • Zuletzt bearbeitet 26.02.2026 16:30:45

Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The application fails to validate the `Origin` header during the WebSocke...

  • EPSS 1.1%
  • Veröffentlicht 02.10.2025 21:15:47
  • Zuletzt bearbeitet 06.10.2025 14:57:05

Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and non default installs between versions 5.8 - 6.0 are vulnerable to unauthenticated local file inclusion attacks which can lead to le...

  • EPSS 0.25%
  • Veröffentlicht 13.08.2024 16:15:09
  • Zuletzt bearbeitet 22.08.2024 14:40:44

Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwise be prote...

Exploit
  • EPSS 17.64%
  • Veröffentlicht 10.04.2024 18:15:07
  • Zuletzt bearbeitet 09.01.2025 16:14:43

Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded through the device image upload API. Attackers have full control over the file contents, full control over the directory where the f...

  • EPSS 90.78%
  • Veröffentlicht 10.04.2024 15:16:04
  • Zuletzt bearbeitet 21.11.2024 08:59:45

Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted upload of file with dangerous type. Since the system allows registration by default, attackers can acquire ordinary user permission...

  • EPSS 0.07%
  • Veröffentlicht 15.01.2024 16:15:11
  • Zuletzt bearbeitet 21.11.2024 08:37:13

Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnerability in File feature allows attackers to execute arbitrary code on the server. This vulnerability is more prevalent because Trac...

  • EPSS 0.06%
  • Veröffentlicht 02.02.2021 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:47:57

Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path vulnerability. Only Windows versions are impacted. Attacker needs write access to the filesystem on the host machine. If Java path ...