Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Traccar

First CVE: Dec 20, 2018Active for: 8 yearsTotal CVEs: 15
48.3
VTI Score
High

Traccar is an open-source GPS tracking platform whose vulnerability footprint centers on its core server product and the web-based management interface that operators use to configure fleets and monitor devices. The vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit code; they cluster around file-handling issues, input validation weaknesses, and authentication gaps that are characteristic of web applications managing trusted operational data without robust input controls. Defenders should treat Traccar deployments as high-value targets if internet-exposed and prioritize patching; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Traccar over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2018
7 years ago
Most Recent CVE
May 26, 2026
59 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-31214CRITICAL
Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded through the device image upload API. Attackers have full contr
Apr 10, 20249.650NOYES
CVE-2025-68930MEDIUM
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerability in the `/api/socket` endpoint. The
Feb 23, 20266.534NOYES
CVE-2018-1000881CRITICAL
Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can
Dec 20, 20189.832NONO
CVE-2026-25648HIGH
Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other
Feb 23, 20268.730NONO
CVE-2019-5748CRITICAL
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
Jan 9, 20199.830NONO
CVE-2026-25649HIGH
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 authorization codes by exploiti
Feb 23, 20268.729NONO
CVE-2024-7746CRITICAL
Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transacti
Aug 13, 20249.827NONO
CVE-2026-27644MEDIUM
Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and comput
May 5, 20266.526NONO
CVE-2023-50729CRITICAL
Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnerability in File feature allows attackers to execute arbitrary
Jan 15, 20249.826NONO
CVE-2026-27694MEDIUM
Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geo
May 5, 20265.423NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
53%
13%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (6.7%)
Network14 (93.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (46.7%)
Unknown0 (0.0%)
Required8 (53.3%)
Privileges Required
Low8 (53.3%)
High0 (0.0%)
None7 (46.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Traccar.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Traccar — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Traccar's Products

View all 3 CNAs →

Top CWEs