CVE-2026-15081

CVE-2026-15081: Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072

Vendor Drupal
Product Location Selector
Weakness CWE-89 · SQLi
Published July 10, 2026
Last update July 10, 2026

CVSS base score

What the vulnerability does

01Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.

Key dates

02Disclosure timeline

July 10, 2026 CVE published