References https://nvd.nist.gov/vuln/detail/CVE-2025-44136 https://github.com/mheranco/CVE-2025-44136 https://github.com/maptiler/tileserver-php/issues/167 https://github.com/advisories/GHSA-cj86-6g7w-75f6 https://access.redhat.com/security/cve/cve-2025-44136 https://www.ameeba.com/blog/cve-2025-44136-critical-cross-site-scripting-vulnerability-in-maptiler-tileserver-php-v2-0/ https://pentest-tools.com/vulnerabilities-exploits/maptiler-tileserver-php-v20-unauthenticated-xss_28115 https://ddpoc.com/DVB-2025-9916.html https://cve.imfht.com/detail/CVE-2025-44136 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-44136.yaml
Related VulnerabilitiesMapTiler-Tileserver-php /tileserver.php/x/1/1/1 目录遍历漏洞(CVE-2025-44137)PoCCVE-2025-44136: MapTiler Tileserver-php v2.0 - Unauthenticated XSSPoCCVE-2025-44137: MapTiler Tileserver-php v2.0 - Unauthenticated File ReadMapTiler Tileserver-php v2.0 存在目录遍历漏洞(CVE-2025-44137)PoCCVE-2020-15500: TileServer GL <=3.0.0 - Cross-Site ScriptingPoCCVE-2024-35627: TileServer API - Cross Site Scripting