Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062

Project: Geolocation FieldDate: 2026-June-24Security risk: Critical 19 ∕ 25 AC:Basic/A:None/CI:All/II:All/E:Theoretical/TD:DefaultVulnerability: SQL InjectionAffected versions: <3.15.0CVE IDs: CVE-2026-13242Description: Geolocation modules adds a field to store coordinates and provides supporting plumbing for views and other modules.
One of the provided views filters does not sufficiently sanitize values if exposed to user input resulting in a SQL injection vulnerability.
This vulnerability is mitigated by the fact that a view must exist, that uses the aforementioned filter and it is set to accept user input.Solution: Install the latest version:

Reported By: 

Fixed By: 

Coordinated By: 

Path to article https://www.drupal.org/sa-contrib-2026-062