References https://nvd.nist.gov/vuln/detail/CVE-2025-44137 https://github.com/mheranco/CVE-2025-44137 https://www.cvedetails.com/cve/CVE-2025-44137/ https://github.com/maptiler/tileserver-php/issues/167 https://access.redhat.com/security/cve/cve-2025-44137 https://devhub.checkmarx.com/cve-details/cve-2025-44137/ https://www.ameeba.com/blog/cve-2025-44137-directory-traversal-vulnerability-in-maptiler-tileserver-php-v2-0/ https://github.com/maptiler/tileserver-php/commit/4fe14e6164bbe2a3f9e3b3d7acf303e3ec210c8e https://blog.csdn.net/HMX404/article/details/157695926 https://ddpoc.com/DVB-2025-9915.html https://www.nsfocus.net/vulndb/129016 https://cve.imfht.com/detail/CVE-2025-44137?lang=en
Related VulnerabilitiesMapTiler-Tileserver-php /tileserver.php/x/1/1/1 目录遍历漏洞(CVE-2025-44137)PoCCVE-2025-44136: MapTiler Tileserver-php v2.0 - Unauthenticated XSSPoCCVE-2025-44137: MapTiler Tileserver-php v2.0 - Unauthenticated File ReadMapTiler Tileserver-php v2.0 存在xss漏洞(CVE-2025-44136)PoCCVE-2020-15500: TileServer GL <=3.0.0 - Cross-Site ScriptingPoCCVE-2024-35627: TileServer API - Cross Site Scripting