Vendorsknowbe4security_awareness_trainingall versions
Vulnerabilities

knowbe4 Security Awareness Training

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-36844
The KnowBe4 Security Awareness Training application before 2020-01-10 allows reflected XSS. The response has a SCRIPT element that sets window.location.href to a JavaScript URL.
Published 2025-04-20 · Analyzed
6.1EPSS 0.003
CVE-2020-36845
The KnowBe4 Security Awareness Training application before 2020-01-10 contains a redirect function that does not validate the destination URL before redirecting. The response has a SCRIPT element that sets window.location.href to an arbitrary https URL.
Published 2025-04-20 · Analyzed
6.1EPSS 0.003