Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4442 articles · 179515 vulns · 37/41 feeds (7d)
← Back to list
7.4
CVE-2026-15081EXPLOITEDPATCHED
drupal · location selector

Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.

Affected Products

VendorProductVersions
drupallocation selector0.0.0

References

  • https://www.drupal.org/sa-contrib-2026-072

Related News (2 articles)

Tier C
VulDB11d ago
CVE-2026-15081 | Drupal Location Selector up to 1.2.x sql injection
→ No new info (linked only)
Tier B
CCCS Canada14d ago
Drupal security advisory (AV26-676)
→ No new info (linked only)
CVSS 3.17.4 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
1.3.0
CWECWE-89
PublishedJul 10, 2026
Last enriched11d agov2
Tags
sql injectioncriticaldrupallocation selector
Trending Score11
Source articles2
Independent2
Info Completeness9/14
Missing: cvss, epss, kev, exploit, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALPRE-CVE
Drupal Internationalization Single Sign-On Access Bypass
Trending: 30
CRITICALCVE-2026-11913
Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045
Trending: 15
MEDIUMCVE-2026-13242
Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062
Trending: 12
MEDIUMCVE-2026-13240
Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060
Trending: 11
CRITICALCVE-2026-12535EXP
Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048
Trending: 11

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 10, 2026
Discovered by ZDM
Jul 10, 2026
Updated: description, severity, activelyExploited
Jul 11, 2026
Actively Exploited
Jul 13, 2026
Patch Available
Jul 13, 2026

Version History

v2
Last enriched 11d ago
v2Tier C11d ago

Updated severity to CRITICAL, marked as actively exploited, and provided a more detailed description of the vulnerability.

descriptionseverityactivelyExploited
via VulDB
v112d ago

Initial creation