CVE-2025-44136

CRITICAL EXPLOITED NUCLEI

Maptiler Tileserver Php - XSS

Title source: rule

Description

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.

Exploits (1)

nomisec WORKING POC
by mheranco · client-side
https://github.com/mheranco/CVE-2025-44136

Nuclei Templates (1)

MapTiler Tileserver-php v2.0 - Unauthenticated XSS
MEDIUMVERIFIEDby 0x_Akoko
Shodan: title:"TileServer-php"
FOFA: title="TileServer-php"

Scores

CVSS v3 9.8
EPSS 0.1144
EPSS Percentile 93.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-11-27
CWE
CWE-79
Status published
Products (1)
maptiler/tileserver_php 2.0
Published Jul 29, 2025
Tracked Since Feb 18, 2026