Maptiler develops mapping and tiling infrastructure, with a focused vulnerability footprint centered on its TileServer PHP product. The observed weakness classes—path traversal and cross-site scripting—reflect input-validation and output-encoding challenges typical of web-facing server applications. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maptiler over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-44136CRITICAL MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html encoding. This leads to XSS and al | Jul 29, 2025 | 9.8 | 39 | NO | YES |
CVE-2025-44137HIGH MapTiler Tileserver-php v2.0 is vulnerable to Directory Traversal. The renderTile function within tileserver.php is responsible for delivering tiles that are stored as files on the | Jul 29, 2025 | 8.2 | 37 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maptiler.
Media articles that mention a CVE ID that affects a product developed by Maptiler — matched by CVE ID, not by vendor name.