Just to add to that.

I really think people should take more interest in securing organisation’s or individual’s data. In my opinion there is a “duty of care” that falls upon a developer even if the client they are developing the product for, doesn’t specifically ask for it.

Because in most cases whoever is using the product is storing data that impacts many other organisations and individuals, not just the person or organisation that bought the product (Bubble app).

Even if you don’t use rich text fields or don’t store images in rich text fields, you should have a level of concern, as this rich text field issue should have been part of the documentation from day one.

In the case of this post the damage is irreversible, and I think Bubble underestimates the reputational and/or operational impacts that can come from this.