CVE-2025-12082: Salsa.digital Civictheme Design System

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0.

Affected products

  • Salsa.digital Civictheme Design System: before 1.12.0 (fixed in 1.12.0)

Published 2025-10-30. Last modified 2026-10-08.