CVE-2026-13242

CVE-2026-13242: Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062

Vendor Drupal
Product Geolocation Field
Weakness CWE-89 · SQLi
Published July 10, 2026
Last update July 10, 2026

CVSS base score

What the vulnerability does

01Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Geolocation Field allows SQL Injection. This issue affects Geolocation Field versions: from 0.0.0 to 3.15.0.

Key dates

02Disclosure timeline

July 10, 2026 CVE published