MapTiler Tileserver-php v2.0 contains a reflected XSS caused by unencoded reflection of the GET parameter \"layer\" in an error message, letting unauthenticated attackers execute arbitrary script on victim browsers.
id: CVE-2025-44136
info:
name: MapTiler Tileserver-php v2.0 - Unauthenticated XSS
author: 0x_Ak
...