Security

VibeMS Security and Responsible Disclosure

Security model

VibeMS is a self-hosted CMS. Website content, CMS users, media, forms, backups and editor data remain on the Customer's chosen hosting environment. Ordinary licensing sends only the information required to administer the licence and signed updates.

Security controls include signed licence certificates, signed release packages, protected private keys, password hashing, role-based access, multi-factor authentication for sensitive operator access, audit logging, HTTPS requirements, backup workflows and restricted update channels.

Security also depends on the Customer maintaining supported PHP and database versions, secure hosting credentials, appropriate file permissions, timely updates, lawful third-party scripts and tested backups.

No software can be guaranteed to be entirely free from vulnerabilities or resistant to every attack. VibeMS does not promise absolute security. This does not reduce agreed product characteristics, statutory defect rights or liability that cannot lawfully be excluded.

Shared responsibility

VibeMS is responsible for vulnerability handling and security corrections for the unmodified, supported VibeMS core during the applicable security-support period. Customers are responsible for their hosting provider and server configuration, administrator access, passwords and recovery codes, backups, imported website code, third-party scripts and integrations, local modifications and installing available security updates within a reasonable period.

A Customer using the editor or operating a self-hosted installation normally does not assume responsibility for a defect in the unmodified VibeMS core. Conversely, VibeMS cannot be responsible for an incident to the extent it was caused by Customer-controlled hosting, credentials, content, configuration, imported code, disabled controls or unsupported modifications.

Reporting a vulnerability

Report suspected vulnerabilities privately to support@vibems.io with the subject Private security report.

Include:

  • affected version and component;
  • prerequisites and reproducible steps;
  • realistic impact;
  • proof of concept using your own test environment;
  • suggested remediation, if available;
  • a safe contact method.

Do not include real customer data, credentials, private keys or destructive payloads.

Safe-harbour expectations

Good-faith research must avoid privacy violations, service disruption, persistence, social engineering, spam, denial of service, accessing data beyond what is necessary to demonstrate the issue, or testing systems belonging to VibeMS Customers without their explicit authorization.

Stop testing and report immediately if personal data, secrets or another person's account become accessible. Allow reasonable time for investigation and remediation before public disclosure. We will acknowledge a credible report, coordinate status updates and credit researchers who request recognition where appropriate.

Supported versions

The VibeMS 1.x product line is scheduled to receive vulnerability handling through 31 July 2031. This date will be extended where mandatory law or the reasonably expected product lifetime requires it. The support end date for later product lines will be published before sale.

Security corrections required by mandatory law during the security-support period are delivered through signed releases without an additional security-update fee. Commercial feature and compatibility update entitlement remains plan-dependent. A security update does not create entitlement to unrelated features or custom support.

Issued security updates remain available for at least the period required by applicable law. Customers should update promptly after testing and should not modify protected core files in production. Unsupported historical versions may require updating to the latest compatible secured release.

Incident contact

Security and privacy incident contact: support@vibems.io and privacy@vibems.io.