CVE-2026-15081: Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/location_selectorto a version that resolves this vulnerability.Fixed in 1.3.0Patch SA-CONTRIB-2026-072
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15081?
CVE-2026-15081 has a risk rating of 76, indicating a critical SQL Injection vulnerability.
How do I fix CVE-2026-15081?
To fix CVE-2026-15081, update the Drupal Location Selector to a version newer than 1.3.0.
What software is affected by CVE-2026-15081?
CVE-2026-15081 affects Drupal Location Selector versions from 0.0.0 to 1.3.0.
What types of attacks can CVE-2026-15081 facilitate?
CVE-2026-15081 can facilitate SQL Injection attacks, allowing unauthorized database access.
When was CVE-2026-15081 published?
CVE-2026-15081 was published on July 10, 2026.