CVE-2026-16007

Summary

AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database.

Affected Software

VendorProductVersion RangeStatus
AppFlowy-IOAppFlowy-Cloud0 <= *affected

Weaknesses

  • CWE-89: CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')

References