AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16007

HIGH · CVSS 7.1

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The SQL injection vulnerability in AppFlowy's qcuiknote feature allows authenticated users to execute arbitrary SQL queries, potentially leading to unauthorized data exfiltration from the underlying database. Organizations utilizing this feature should prioritize patching to mitigate the risk of data breaches and protect sensitive information. Immediate action is recommended for any entities relying on AppFlowy for data management.

CVE
CVE-2026-16007
Severity
HIGH
CVSS
7.1
EPSS
N/A

Original NVD Description

AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database.