[CVE-2026-16007] AppFlowy Authenticated SQL Injection
projectblack.io | vulnerability | CVE-2026-16007 | #sql-injection | #web-security | #vulnerability | #disclosure | #appflowy | #cve-2026-16007
Summary
Project Black details CVE-2026-16007, an authenticated SQL injection in AppFlowy: the quick-note search parameter reaches the SQL query unsanitized—plus a telling vendor response.
Why it matters
This vulnerability coverage helps defenders validate exposure and prioritize remediation.
- Vendor
- AppFlowy
- Product
- AppFlowy
- Published
- Collected
Skip to content