DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE_AT variable) to doku.php and updated package is fixed by added patch from upstream.
{ "section": "core" }