Keeping Jimdo secure is our job, so you shouldn't normally come across any security vulnerabilities. If you do think you have found one, please let us know so we can look into it. This article explains what to report, how to send us your report, and what to keep in mind.
In this article:
- What counts as a security vulnerability
- How to report a vulnerability
- Please keep in mind
- What happens next
What counts as a security vulnerability
A security vulnerability is a weakness in Jimdo's platform or services that could allow someone to access data, accounts or functions they shouldn't have access to.
Some issues are not vulnerabilities and have their own help articles:
- If you think someone has access to your account, read What should I do if my account has been hacked?
- If you received a suspicious email that claims to be from Jimdo, read How do I recognize a fake or scam email (phishing)?
How to report a vulnerability
Please contact our Support team and describe what you found. To help us look into it quickly, please include:
- A short description of the vulnerability and its possible impact
- The affected website, page or URL
- The steps needed to reproduce the issue
- Screenshots or other evidence, if available
- When you found the issue
Important: Never send us passwords or other login details, including your own.
Please keep in mind
- Only test your own Jimdo website. Do not access, change or delete data that belongs to other customers.
- Denial of Service tests and load tests are not permitted.
- Please don't share details of the vulnerability publicly until we have had the chance to look into it.
For more information about testing your own website, read Can I test my website for security issues?
What happens next
Our Support team forwards your report to our security team, who will review it. Thank you for helping us keep Jimdo secure.