CVE-2026-16007
AppFlowy Authenticated SQL Injection
AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database.
https://www.cve.org/CVERecord?id=CVE-2026-16007
AppFlowy Authenticated SQL Injection
The actual bug isn’t the interesting part in this case, it was the vendor’s response - although it’s crazy that we’re still finding SQL injection in 2026.

