This document outlines security procedures and general policies for the Admidio project.
The Admidio team and community take the security of Admidio seriously. We appreciate your efforts to responsibly disclose security vulnerabilities and help keep Admidio secure.
If you discover a security vulnerability, please create a GitHub Security Advisory in the Admidio repository. This allows us to discuss the issue privately, coordinate a fix, and prepare a responsible disclosure before the vulnerability becomes public.
If you would like to provide additional information or are unable to use GitHub Security Advisories, you may also contact the maintainer by email at m.fassbender@admidio.org.
We aim to acknowledge your report within 3 business days. After the initial response, we will keep you informed about the progress of the investigation, the development of a fix, and the coordinated public disclosure. We may contact you if we need additional information to reproduce or understand the issue.
Please report security vulnerabilities in third-party plugins directly to the respective plugin maintainer, as those plugins are maintained independently from the Admidio core project.
Thank you for helping make Admidio more secure.
Here you find a short overview about our versions that we will support with security updates.
| Version | Supported |
|---|---|
| >= 5.1.x | ✅ |
| 5.0.x | ✅ |
| <= 4.x | ❌ |
If you have suggestions on how this process could be improved please submit a pull request.