SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15081

HIGH · CVSS 7.4 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

The Drupal Location Selector component, versions 0.0.0 to 1.3.0, is vulnerable to SQL injection due to improper handling of special elements in SQL commands. This flaw could allow attackers to execute arbitrary SQL queries, potentially compromising the integrity and confidentiality of the database. Organizations using affected versions of the Location Selector should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-15081
Severity
HIGH
CVSS
7.4
EPSS
0.26%

Original NVD Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.