CVE-2025-44136

CRITICAL EXPLOITED NUCLEI

MapTiler Tileserver-php v2.0 - Unauthenticated Reflected Cross-Site Scripting via Layer Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-44136 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including mheranco. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a proof-of-concept for an unauthenticated reflected XSS vulnerability in MapTiler Tileserver-php v2.0. The exploit leverages the 'layer' GET parameter to inject arbitrary JavaScript code, which is reflected in an error message without proper HTML encoding.

Description

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victim's browser.

Exploits (1)

nomisec WORKING POC
by mheranco · client-side
https://github.com/mheranco/CVE-2025-44136

This repository contains a proof-of-concept for an unauthenticated reflected XSS vulnerability in MapTiler Tileserver-php v2.0. The exploit leverages the 'layer' GET parameter to inject arbitrary JavaScript code, which is reflected in an error message without proper HTML encoding.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: MapTiler Tileserver-php v2.0
No auth needed
Prerequisites: Access to the target tileserver.php endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

MapTiler Tileserver-php v2.0 - Unauthenticated XSS
MEDIUMVERIFIEDby 0x_Akoko
Shodan: title:"TileServer-php"
FOFA: title="TileServer-php"

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.1302
EPSS Percentile 94.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2025-11-27
CWE
CWE-79
Status published
Products (1)
maptiler/tileserver_php 2.0
Published Jul 29, 2025
Tracked Since Feb 18, 2026