Drupal · Geolocation Field · CVE-2026-13242
**Name of the Vulnerable Software and Affected Versions**
Drupal Geolocation Field versions 0.0.0 through 3.15.0
**Description**
An SQL injection issue exists in the Drupal Geolocation Field module, which provides functionality to store coordinates and supports views and other modules. The problem occurs because one of the views filters does not sufficiently sanitize values when they are exposed to user input. This allows for the improper neutralization of special elements used in an SQL command. The risk is limited to scenarios where a view is configured to use the affected filter and is set to accept user input.
**Recommendations**
Update Drupal Geolocation Field to a version later than 3.15.0.