CVE-2026-16007

AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-15 06:16

Updated : 2026-09-09 15:52


NVD link : CVE-2026-16007

Mitre link : CVE-2026-16007

CVE.ORG link : CVE-2026-16007


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')