Traccar is an open-source GPS tracking platform whose vulnerability footprint centers on its core server product and the web-based management interface that operators use to configure fleets and monitor devices. The vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit code; they cluster around file-handling issues, input validation weaknesses, and authentication gaps that are characteristic of web applications managing trusted operational data without robust input controls. Defenders should treat Traccar deployments as high-value targets if internet-exposed and prioritize patching; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Traccar over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-31214CRITICAL Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded through the device image upload API. Attackers have full contr | Apr 10, 2024 | 9.6 | 50 | NO | YES |
CVE-2025-68930MEDIUM Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The | Feb 23, 2026 | 6.5 | 34 | NO | YES |
CVE-2018-1000881CRITICAL Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can | Dec 20, 2018 | 9.8 | 32 | NO | NO |
CVE-2026-25648HIGH Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other | Feb 23, 2026 | 8.7 | 30 | NO | NO |
CVE-2019-5748CRITICAL In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks. | Jan 9, 2019 | 9.8 | 30 | NO | NO |
CVE-2026-25649HIGH Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization codes by exploiti | Feb 23, 2026 | 8.7 | 29 | NO | NO |
CVE-2024-7746CRITICAL Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transacti | Aug 13, 2024 | 9.8 | 27 | NO | NO |
CVE-2026-27644MEDIUM Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and comput | May 5, 2026 | 6.5 | 26 | NO | NO |
CVE-2023-50729CRITICAL Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnerability in File feature allows attackers to execute arbitrary | Jan 15, 2024 | 9.8 | 26 | NO | NO |
CVE-2026-27694MEDIUM Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geo | May 5, 2026 | 5.4 | 23 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Traccar.
Media articles that mention a CVE ID that affects a product developed by Traccar — matched by CVE ID, not by vendor name.