phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-26934.json"