shouldiuse.io

Categories

VERDICT

Should I use VitalPBX?

Open-source PBX GUI built on Asterisk - vitalpbx.com

Depends. Buy if you have Linux/VoIP admin skills and want self-hosted, multi-tenant telephony without per-user fees. Skip it if you just need working phones — hosted VoIP is simpler and safer for non-experts.

Confidence

Medium. Based on ~20 public sources; most snippets truncated, so specifics are partial. No named customer companies found in evidence.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityOnly 17 Trustpilot reviews; no clear signal
  • Security posture

Pricing

Free

Open-source self-hosted

ModelNo per-user fees
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Multi-Tenant Plan≈250 (currency/period unclear in source)
Add-ons (Sonata dialer, billing, etc.)Separate purchase

Best for

  • IT teams self-hosting business phone systems
  • VoIP resellers running multi-tenant PBX
  • Call centers (paid Sonata add-on)
  • High-headcount orgs avoiding per-user fees

Not for

  • Small teams wanting plug-and-play phone apps
  • Buyers with no Linux/VoIP admin on staff
  • Anyone who won't patch exposed servers fast
  • Single-office shops that just need calls to work

Gotchas - check before you buy

high

Old 3.2.x builds had unauthenticated account-takeover bugs; never expose an unpatched PBX to the internet

medium

Vendor's own blog stresses toll-fraud risk once a PBX is compromised — self-hosting carries real liability

medium

Call-center, dialer, multi-tenant, and billing features sit behind paid plans and add-ons

low

Guess: simultaneous-call pricing can spike costs during call bursts versus flat per-user hosted plans

Pros and cons

Pros

  • No per-user fees; priced by instance and simultaneous calls
  • Open-source core: a full GUI on top of Asterisk
  • Multi-tenant plan runs PBX for many clients on one instance
  • Reddit users report switching to it from 3CX
  • Regular releases with security patches, e.g., 4.5.3 R7

Cons

  • History of critical CVEs, including account-takeover flaws in 3.2.x
  • Self-hosted: firewalling, upgrades, and SIP security are your job
  • Users report end-user documentation is thin
  • Call-center and multi-tenant features require paid plans or add-ons
  • Tiny review base (17 Trustpilot ratings) limits quality signal

Sources & method

Analyzed 9/30/2026 - 14 sources - Active CVE history 2022–2024 including unauthenticated account-takeover flaws; vendor patches promptly. Stay current and firewall it.

official x3review x6security x3news x2
  • CVE-2024-24386, Issue in VitalPBX v3.2.4-5 allowing attacker access (NVD listing).
  • Reflected XSS account takeover, VitalPBX 3.2.3-8 vulnerable to account takeover via reflected XSS.
  • CSRF account takeover, VitalPBX 3.2.3-8 also vulnerable to account takeover via CSRF.
  • CVE-2022-29330, 0-day in versions below 3.2.1, disclosed June 2022.

Key stats

  • Value for money: 4/5

    Rating

  • Free

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 4/5. No per-user fees, open core; add-ons cost extra
  • Ease of use: 3/5. GUI over raw Asterisk; users report doc gaps
  • Feature depth: 4/5. Multi-tenant, call-center, hotel, CRM integrations in evidence
  • Support quality. Only 17 Trustpilot reviews; no clear signal
  • Security posture: 2/5. Repeat account-takeover CVEs; patches ship quickly
  • 17 reviews Trustpilot tiny sample; no consensus rating visible
  • Yes Free tier open-source core; paid plans and add-ons
  • No per-user fees Pricing model priced by instance / simultaneous calls
  • 4+ since 2022 Public CVEs XSS, CSRF, 0-day; older 3.2.x versions

Pricing

Open-source self-hosted

Free

  • Core PBX GUI on Asterisk
  • Community forum support

Multi-Tenant Plan

≈250 (currency/period unclear in source)

  • Run many tenants on one instance
  • No per-user fees

Add-ons (Sonata dialer, billing, etc.)

Separate purchase

  • Call-center modules
  • Billing and reporting

Security

Active CVE history 2022–2024 including unauthenticated account-takeover flaws; vendor patches promptly.

  • CVE-2024-24386Issue in VitalPBX v3.2.4-5 allowing attacker access (NVD listing).⁷
  • Reflected XSS account takeoverVitalPBX 3.2.3-8 vulnerable to account takeover via reflected XSS.⁸

Stay current and firewall it.

  • CSRF account takeoverVitalPBX 3.2.3-8 also vulnerable to account takeover via CSRF.
  • CVE-2022-293300-day in versions below 3.2.1, disclosed June 2022.⁹

What users say

Reddit and forum users adopt VitalPBX as a 3CX/FreePBX alternative for its feature depth, while flagging thin documentation.

Alternatives

Compare VitalPBX with each alternative.

  • Hosted VoIP (RingCentral, OpenPhone)

    Simpler for small teams — no server to run or secure.

Full analysis

Based on ~20 public sources; most snippets truncated, so specifics are partial. No named customer companies found in evidence.

Powerful self-hosted Asterisk PBX, no per-user fees — but you own the security. Small teams: buy hosted VoIP instead.

Methodology

Based on ~20 public sources; most snippets truncated, so specifics are partial. No named customer companies found in evidence.

Sources

  1. review
  2. review
  3. SourceForge reviewssourceforge.net
    review
  4. review
  5. review
  6. review
  7. security
  8. security
  9. security
  10. official
  11. news
  12. official
  13. news
  14. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.