CVE-2020-36844: KNOWBE4 Security Awareness Training

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The KnowBe4 Security Awareness Training application before 2020-01-10 allows reflected XSS. The response has a SCRIPT element that sets window.location.href to a JavaScript URL.

Affected products

  • KNOWBE4 Security Awareness Training: before 2020-01-10 (fixed in 2020-01-10)

Published 2025-04-20. Last modified 2026-06-17.