1.
projectblack.io | vulnerability | | original ↗ | #sql-injection | #web-security | #vulnerability | #disclosure
Project Black details CVE-2026-16007, an authenticated SQL injection in AppFlowy: the quick-note search parameter reaches the SQL query unsanitized—plus a telling vendor response.
Why it matters: This vulnerability coverage helps defenders validate exposure and prioritize remediation.
Skip to content