Should I use VitalPBX?
Open-source PBX GUI built on Asterisk - vitalpbx.com
Depends. Buy if you have Linux/VoIP admin skills and want self-hosted, multi-tenant telephony without per-user fees. Skip it if you just need working phones — hosted VoIP is simpler and safer for non-experts.
Confidence
Medium. Based on ~20 public sources; most snippets truncated, so specifics are partial. No named customer companies found in evidence.
Ratings
- Value for money
- Ease of use
- Feature depth
- Support qualityOnly 17 Trustpilot reviews; no clear signal
- Security posture
Pricing
Free
Open-source self-hosted
ModelNo per-user fees
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Multi-Tenant Plan≈250 (currency/period unclear in source)
Add-ons (Sonata dialer, billing, etc.)Separate purchase
Best for
- →IT teams self-hosting business phone systems
- →VoIP resellers running multi-tenant PBX
- →Call centers (paid Sonata add-on)
- →High-headcount orgs avoiding per-user fees
Not for
- ×Small teams wanting plug-and-play phone apps
- ×Buyers with no Linux/VoIP admin on staff
- ×Anyone who won't patch exposed servers fast
- ×Single-office shops that just need calls to work
Gotchas - check before you buy
high
Old 3.2.x builds had unauthenticated account-takeover bugs; never expose an unpatched PBX to the internet
medium
Vendor's own blog stresses toll-fraud risk once a PBX is compromised — self-hosting carries real liability
medium
Call-center, dialer, multi-tenant, and billing features sit behind paid plans and add-ons
low
Guess: simultaneous-call pricing can spike costs during call bursts versus flat per-user hosted plans
Pros and cons
Pros
- +No per-user fees; priced by instance and simultaneous calls
- +Open-source core: a full GUI on top of Asterisk
- +Multi-tenant plan runs PBX for many clients on one instance
- +Reddit users report switching to it from 3CX
- +Regular releases with security patches, e.g., 4.5.3 R7
Cons
- −History of critical CVEs, including account-takeover flaws in 3.2.x
- −Self-hosted: firewalling, upgrades, and SIP security are your job
- −Users report end-user documentation is thin
- −Call-center and multi-tenant features require paid plans or add-ons
- −Tiny review base (17 Trustpilot ratings) limits quality signal
Sources & method
Analyzed 9/30/2026 - 14 sources - Active CVE history 2022–2024 including unauthenticated account-takeover flaws; vendor patches promptly. Stay current and firewall it.
official x3review x6security x3news x2
- CVE-2024-24386, Issue in VitalPBX v3.2.4-5 allowing attacker access (NVD listing).
- Reflected XSS account takeover, VitalPBX 3.2.3-8 vulnerable to account takeover via reflected XSS.
- CSRF account takeover, VitalPBX 3.2.3-8 also vulnerable to account takeover via CSRF.
- CVE-2022-29330, 0-day in versions below 3.2.1, disclosed June 2022.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.