Personal Management System is a narrowly scoped vendor with a single product offering that has achieved notable prominence in the vulnerability landscape despite its focused footprint. The observed disclosures cluster around a modest volume and reflect vulnerabilities that merit standard development and patching practices rather than heightened urgency. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Personal Management System over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-29319CRITICAL Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a se | Jul 5, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-43838HIGH An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avata | Oct 4, 2023 | 7.8 | 22 | NO | NO |
CVE-2025-29454MEDIUM An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function. | Apr 17, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-29456MEDIUM An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function. | Apr 17, 2025 | 6.5 | 18 | NO | NO |
CVE-2025-29453MEDIUM An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component. | Apr 17, 2025 | 6.5 | 18 | NO | NO |
CVE-2025-29455MEDIUM An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function. | Apr 17, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-29318MEDIUM Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code. | Jul 5, 2024 | 5.4 | 17 | NO | NO |
CVE-2025-28355MEDIUM Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the S | Apr 18, 2025 | 4.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Personal Management System.
Media articles that mention a CVE ID that affects a product developed by Personal Management System — matched by CVE ID, not by vendor name.