CVE-2025-44136
CRITICAL EXPLOITED NUCLEIMaptiler Tileserver Php - XSS
Title source: ruleDescription
MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.
Exploits (1)
Nuclei Templates (1)
MapTiler Tileserver-php v2.0 - Unauthenticated XSS
MEDIUMVERIFIEDby 0x_Akoko
Shodan:
title:"TileServer-php"
FOFA:
title="TileServer-php"
Scores
CVSS v3
9.8
EPSS
0.1144
EPSS Percentile
93.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2025-11-27
CWE
CWE-79
Status
published
Products (1)
maptiler/tileserver_php
2.0
Published
Jul 29, 2025
Tracked Since
Feb 18, 2026