{"id":"CVE-2026-16007","title":"AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability","summary":"AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database.","severity":"none","cwe":["CWE-89"],"published":"2026-08-15","updated":"2026-09-09","sourceUpdated":"2026-09-09T15:52:04.827","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-16007","references":[{"url":"https://projectblack.io/blog/appflowy-authenticated-sql-injection/","label":"ab69c47f-b95e-4bf2-b2d9-4b1fd1b24b4a"}],"tags":["nvd"],"epss":0.00203,"epssPercentile":0.10601,"ingestedAt":"2026-08-16T04:33:12.485Z","slug":"CVE-2026-16007","body":"## Overview\n\nAppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}