AppFlowy leaves its self-hosted edition exposed to an authenticated SQL injection
CVE-2026-16007 is an authenticated SQL injection in AppFlowy Cloud, the open-source Notion alternative: any logged-in user can read, modify, or drop the database. The fix exists only for the commercial tier — the self-hosted edition got no answer from the vendor.