๐Ÿ” CVE Alert

CVE-2026-16007

UNKNOWN 0.0

Authenticated SQL Injection in AppFlowy

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database.

CWE CWE-89
Vendor appflowy-io
Product appflowy-cloud
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for appflowy-io appflowy-cloud

Be the first to know when new unknown vulnerabilities affecting appflowy-io appflowy-cloud are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

AppFlowy-IO / AppFlowy-Cloud
0 โ‰ค *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
projectblack.io: https://projectblack.io/blog/appflowy-authenticated-sql-injection/