Adminer through 4.7.8 allows XSS via the history parameter to the default URI.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-35572.json"