You're in the EU and the vulnerability affects PII, so I'd recommend informing your country's Data Protection Authority of the risk.
If you make a public disclosure, you are at risk of being bullied by lawyers at the very least. Handing the issue over to the regulators might be more or less effective than making a public disclosure, but it should offer you some protection against liability and legal threats. As I understand it, most EU member states have some form of legislation to protect whistleblowers against defamation suits.
http://ec.europa.eu/justice/data-protection/article-29/struc...