phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-26934.json"