GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6d5e6ea65d5e6ea65d5e6ea65d5e6ea65d5e6ea65
GraphQL introspection enabled at /api/graphql Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d60479c685c36ad747762d0ab155eafb05dab91a0e
GraphQL introspection enabled at /api/graphql Types: 435 (by kind: ENUM: 27, INPUT_OBJECT: 101, INTERFACE: 18, OBJECT: 284, SCALAR: 5) Operations: - Query: Query | fields: categories, category, categoryList, customAttributeMetadata, products Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 categories (args: optional/default) : total_count=7 products (args: optional/default) : total_count=1139
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d60479c685c36ad747762d0ab155eafb0555eafb05
GraphQL introspection enabled at /api/graphql Types: 435 (by kind: ENUM: 27, INPUT_OBJECT: 101, INTERFACE: 18, OBJECT: 284, SCALAR: 5) Operations: - Query: Query | fields: categories, category, categoryList, customAttributeMetadata, products Directives: deprecated, include, skip, specifiedBy (total: 4)
Open service 151.101.131.10:443 · dev.buenamesa.com
2026-01-22 21:04
HTTP/1.1 200 OK
Connection: close
Content-Length: 44063
x-frame-options: SAMEORIGIN
cache-control: max-age=300,stale-while-revalidate=300
x-frame-options: SAMEORIGIN
last-modified: Thu, 22 Jan 2026 11:54:09 GMT
etag: "ac1f-648f8b2d15246"
x-vhost: buenamesa.com
content-type: text/html;charset=utf-8
X-Content-Type-Options: nosniff
Accept-Ranges: bytes
Date: Thu, 22 Jan 2026 21:04:10 GMT
Age: 1
Strict-Transport-Security: max-age=31557600
X-Served-By: cache-yyz4575-YYZ
X-Cache: HIT
X-Timer: S1769115851.568140,VS0,VS0,VE4
Vary: Accept-Encoding
Page title: Buena Mesa Home
<!DOCTYPE HTML>
<html lang="en">
<head>
<head>
<title class="mainPageTitle">Buena Mesa Home</title>
</head>
<meta class="pageDesc" name="description" content="buena mesa"/>
<meta name="template" content="buenamesa-freeform-template"/>
<meta name="viewport" content="width=device-width, initial-scale=1"/>
<script defer="defer" type="text/javascript" src="/.rum/@adobe/helix-rum-js@%5E2/dist/rum-standalone.js"></script>
<script src="https://kit.fontawesome.com/136d59004e.js" crossorigin="anonymous" defer></script>
<script src="https://www.youtube.com/iframe_api"></script>
<script type="text/javascript">
(function() {
window.ContextHub = window.ContextHub || {};
/* setting paths */
ContextHub.Paths = ContextHub.Paths || {};
ContextHub.Paths.CONTEXTHUB_PATH = "/libs/settings/cloudsettings/legacy/contexthub";
ContextHub.Paths.RESOURCE_PATH = "\/content\/buenamesa\/us\/en\/_jcr_content\/contexthub";
ContextHub.Paths.SEGMENTATION_PATH = "";
ContextHub.Paths.CQ_CONTEXT_PATH = "";
/* setting initial constants */
ContextHub.Constants = ContextHub.Constants || {};
ContextHub.Constants.ANONYMOUS_HOME = "/home/users/5/5nQ6sQ_MOeL9fBsrnori";
ContextHub.Constants.MODE = "no-ui";
}());
</script><script src="/etc/cloudsettings.kernel.js/libs/settings/cloudsettings/legacy/contexthub" type="text/javascript"></script>
<script>
/* Start of MikMak tag */
(function(e,d){try{var a=window.swnDataLayer=window.swnDataLayer||{};a.appId=e||a.appId,a.eventBuffer=a.eventBuffer||[],a.loadBuffer=a.loadBuffer||[],a.push=a.push||function(e){a.eventBuffer.push(e)},a.load=a.load||function(e){a.loadBuffer.push(e)},a.dnt=a.dnt!=null?a.dnt:d;var t=document.getElementsByTagName("script")[0],n=document.createElement("script");n.async=!0,n.src="//wtb-tag.mikmak.ai/scripts/"+a.appId+"/tag.min.js",t.parentNode.insertBefore(n,t)}catch(e){console.log(e)}}("68cb4fc191899fdb207ce7a3", false));
/* End of MikMak tag */
</script>
<link rel="stylesheet" href="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-tyson-core.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-dependencies-buenamesa.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-site-buenamesa.lc-2625c9ceabeb419b7e3d6345c739c6ed-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-base.lc-9222ec5da99d65c4c6fc2c8b9e4b4c77-lc.min.css" type="text/css">
<link rel="canonical" href="https://dev.buenamesa.com/"/>
<!-- meta -->
<meta charset="UTF-8"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-16x16.png" rel="icon" type="image/png" sizes="16x16"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-32x32.png" rel="icon" type="image/png" sizes="32x32"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/apple-touch-icon.png" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<link href="/themes/custom/tfs/favicons/apple-touch-icon.png?v=XS8BSoObZc" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<meta name="image" content="/content/dam/buenamesa/logos/hero-image-3.jpg"/>
<meta name="language-code" content="en"/>
<meta class="swiftype" name="page_id" data-type="string" content="1001807632"/>
<!--// meta -->
<script type="text/javascript" src="//assets.adobedtm.com/4b84b345350f/d08e96ac7cf8/launch-892d9bb32fe7-development.min.js" async></script>
<script src="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-t
Open service 151.101.131.10:443 · dev.buenamesa.com
2026-01-09 01:47
HTTP/1.1 200 OK
Connection: close
Content-Length: 44063
x-frame-options: SAMEORIGIN
cache-control: max-age=300,stale-while-revalidate=300
x-frame-options: SAMEORIGIN
last-modified: Fri, 09 Jan 2026 01:47:55 GMT
etag: W/"ac1f-647eab6cc53b8"
x-vhost: buenamesa.com
content-type: text/html;charset=utf-8
X-Content-Type-Options: nosniff
Accept-Ranges: bytes
Date: Fri, 09 Jan 2026 01:47:55 GMT
Age: 0
Strict-Transport-Security: max-age=31557600
X-Served-By: cache-fra-eddf8230073-FRA
X-Cache: HIT
X-Timer: S1767923272.347558,VS0,VS0,VE2909
Vary: Accept-Encoding
Page title: Buena Mesa Home
<!DOCTYPE HTML>
<html lang="en">
<head>
<head>
<title class="mainPageTitle">Buena Mesa Home</title>
</head>
<meta class="pageDesc" name="description" content="buena mesa"/>
<meta name="template" content="buenamesa-freeform-template"/>
<meta name="viewport" content="width=device-width, initial-scale=1"/>
<script defer="defer" type="text/javascript" src="/.rum/@adobe/helix-rum-js@%5E2/dist/rum-standalone.js"></script>
<script src="https://kit.fontawesome.com/136d59004e.js" crossorigin="anonymous" defer></script>
<script src="https://www.youtube.com/iframe_api"></script>
<script type="text/javascript">
(function() {
window.ContextHub = window.ContextHub || {};
/* setting paths */
ContextHub.Paths = ContextHub.Paths || {};
ContextHub.Paths.CONTEXTHUB_PATH = "/libs/settings/cloudsettings/legacy/contexthub";
ContextHub.Paths.RESOURCE_PATH = "\/content\/buenamesa\/us\/en\/_jcr_content\/contexthub";
ContextHub.Paths.SEGMENTATION_PATH = "";
ContextHub.Paths.CQ_CONTEXT_PATH = "";
/* setting initial constants */
ContextHub.Constants = ContextHub.Constants || {};
ContextHub.Constants.ANONYMOUS_HOME = "/home/users/5/5nQ6sQ_MOeL9fBsrnori";
ContextHub.Constants.MODE = "no-ui";
}());
</script><script src="/etc/cloudsettings.kernel.js/libs/settings/cloudsettings/legacy/contexthub" type="text/javascript"></script>
<script>
/* Start of MikMak tag */
(function(e,d){try{var a=window.swnDataLayer=window.swnDataLayer||{};a.appId=e||a.appId,a.eventBuffer=a.eventBuffer||[],a.loadBuffer=a.loadBuffer||[],a.push=a.push||function(e){a.eventBuffer.push(e)},a.load=a.load||function(e){a.loadBuffer.push(e)},a.dnt=a.dnt!=null?a.dnt:d;var t=document.getElementsByTagName("script")[0],n=document.createElement("script");n.async=!0,n.src="//wtb-tag.mikmak.ai/scripts/"+a.appId+"/tag.min.js",t.parentNode.insertBefore(n,t)}catch(e){console.log(e)}}("68cb4fc191899fdb207ce7a3", false));
/* End of MikMak tag */
</script>
<link rel="stylesheet" href="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-tyson-core.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-dependencies-buenamesa.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-site-buenamesa.lc-ba0804a2408c34972016bb159f46b1b6-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-base.lc-9222ec5da99d65c4c6fc2c8b9e4b4c77-lc.min.css" type="text/css">
<link rel="canonical" href="https://dev.buenamesa.com/"/>
<!-- meta -->
<meta charset="UTF-8"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-16x16.png" rel="icon" type="image/png" sizes="16x16"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-32x32.png" rel="icon" type="image/png" sizes="32x32"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/apple-touch-icon.png" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<link href="/themes/custom/tfs/favicons/apple-touch-icon.png?v=XS8BSoObZc" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<meta name="image" content="/content/dam/buenamesa/logos/hero-image-3.jpg"/>
<meta name="language-code" content="en"/>
<meta class="swiftype" name="page_id" data-type="string" content="1001807632"/>
<!--// meta -->
<script type="text/javascript" src="//assets.adobedtm.com/4b84b345350f/d08e96ac7cf8/launch-892d9bb32fe7-development.min.js" async></script>
<script src="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-t
Open service 151.101.131.10:443 · dev.buenamesa.com
2026-01-02 05:31
HTTP/1.1 200 OK
Connection: close
Content-Length: 44063
x-frame-options: SAMEORIGIN
cache-control: max-age=300,stale-while-revalidate=300
x-frame-options: SAMEORIGIN
last-modified: Thu, 01 Jan 2026 09:42:09 GMT
etag: "ac1f-64750681808de"
x-vhost: buenamesa.com
content-type: text/html;charset=utf-8
X-Content-Type-Options: nosniff
Accept-Ranges: bytes
Date: Fri, 02 Jan 2026 05:31:05 GMT
Age: 0
Strict-Transport-Security: max-age=31557600
X-Served-By: cache-lga21986-LGA
X-Cache: HIT
X-Timer: S1767331865.044800,VS0,VS0,VE1
Vary: Accept-Encoding
Page title: Buena Mesa Home
<!DOCTYPE HTML>
<html lang="en">
<head>
<head>
<title class="mainPageTitle">Buena Mesa Home</title>
</head>
<meta class="pageDesc" name="description" content="buena mesa"/>
<meta name="template" content="buenamesa-freeform-template"/>
<meta name="viewport" content="width=device-width, initial-scale=1"/>
<script defer="defer" type="text/javascript" src="/.rum/@adobe/helix-rum-js@%5E2/dist/rum-standalone.js"></script>
<script src="https://kit.fontawesome.com/136d59004e.js" crossorigin="anonymous" defer></script>
<script src="https://www.youtube.com/iframe_api"></script>
<script type="text/javascript">
(function() {
window.ContextHub = window.ContextHub || {};
/* setting paths */
ContextHub.Paths = ContextHub.Paths || {};
ContextHub.Paths.CONTEXTHUB_PATH = "/libs/settings/cloudsettings/legacy/contexthub";
ContextHub.Paths.RESOURCE_PATH = "\/content\/buenamesa\/us\/en\/_jcr_content\/contexthub";
ContextHub.Paths.SEGMENTATION_PATH = "";
ContextHub.Paths.CQ_CONTEXT_PATH = "";
/* setting initial constants */
ContextHub.Constants = ContextHub.Constants || {};
ContextHub.Constants.ANONYMOUS_HOME = "/home/users/5/5nQ6sQ_MOeL9fBsrnori";
ContextHub.Constants.MODE = "no-ui";
}());
</script><script src="/etc/cloudsettings.kernel.js/libs/settings/cloudsettings/legacy/contexthub" type="text/javascript"></script>
<script>
/* Start of MikMak tag */
(function(e,d){try{var a=window.swnDataLayer=window.swnDataLayer||{};a.appId=e||a.appId,a.eventBuffer=a.eventBuffer||[],a.loadBuffer=a.loadBuffer||[],a.push=a.push||function(e){a.eventBuffer.push(e)},a.load=a.load||function(e){a.loadBuffer.push(e)},a.dnt=a.dnt!=null?a.dnt:d;var t=document.getElementsByTagName("script")[0],n=document.createElement("script");n.async=!0,n.src="//wtb-tag.mikmak.ai/scripts/"+a.appId+"/tag.min.js",t.parentNode.insertBefore(n,t)}catch(e){console.log(e)}}("68cb4fc191899fdb207ce7a3", false));
/* End of MikMak tag */
</script>
<link rel="stylesheet" href="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-tyson-core.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-dependencies-buenamesa.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-site-buenamesa.lc-2625c9ceabeb419b7e3d6345c739c6ed-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-base.lc-9222ec5da99d65c4c6fc2c8b9e4b4c77-lc.min.css" type="text/css">
<link rel="canonical" href="https://dev.buenamesa.com/"/>
<!-- meta -->
<meta charset="UTF-8"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-16x16.png" rel="icon" type="image/png" sizes="16x16"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-32x32.png" rel="icon" type="image/png" sizes="32x32"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/apple-touch-icon.png" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<link href="/themes/custom/tfs/favicons/apple-touch-icon.png?v=XS8BSoObZc" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<meta name="image" content="/content/dam/buenamesa/logos/hero-image-3.jpg"/>
<meta name="language-code" content="en"/>
<meta class="swiftype" name="page_id" data-type="string" content="1001807632"/>
<!--// meta -->
<script type="text/javascript" src="//assets.adobedtm.com/4b84b345350f/d08e96ac7cf8/launch-892d9bb32fe7-development.min.js" async></script>
<script src="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-t
Open service 151.101.131.10:443 · dev.buenamesa.com
2025-12-22 11:26
HTTP/1.1 200 OK
Connection: close
Content-Length: 44063
x-frame-options: SAMEORIGIN
cache-control: max-age=300,stale-while-revalidate=300
x-frame-options: SAMEORIGIN
last-modified: Mon, 22 Dec 2025 11:26:52 GMT
etag: W/"ac1f-64688b4253b39"
x-vhost: buenamesa.com
content-type: text/html;charset=utf-8
X-Content-Type-Options: nosniff
Accept-Ranges: bytes
Date: Mon, 22 Dec 2025 11:26:52 GMT
Age: 0
Strict-Transport-Security: max-age=31557600
X-Served-By: cache-bom-vanm7210056-BOM
X-Cache: HIT
X-Timer: S1766402807.408758,VS0,VS0,VE5176
Vary: Accept-Encoding
Page title: Buena Mesa Home
<!DOCTYPE HTML>
<html lang="en">
<head>
<head>
<title class="mainPageTitle">Buena Mesa Home</title>
</head>
<meta class="pageDesc" name="description" content="buena mesa"/>
<meta name="template" content="buenamesa-freeform-template"/>
<meta name="viewport" content="width=device-width, initial-scale=1"/>
<script defer="defer" type="text/javascript" src="/.rum/@adobe/helix-rum-js@%5E2/dist/rum-standalone.js"></script>
<script src="https://kit.fontawesome.com/136d59004e.js" crossorigin="anonymous" defer></script>
<script src="https://www.youtube.com/iframe_api"></script>
<script type="text/javascript">
(function() {
window.ContextHub = window.ContextHub || {};
/* setting paths */
ContextHub.Paths = ContextHub.Paths || {};
ContextHub.Paths.CONTEXTHUB_PATH = "/libs/settings/cloudsettings/legacy/contexthub";
ContextHub.Paths.RESOURCE_PATH = "\/content\/buenamesa\/us\/en\/_jcr_content\/contexthub";
ContextHub.Paths.SEGMENTATION_PATH = "";
ContextHub.Paths.CQ_CONTEXT_PATH = "";
/* setting initial constants */
ContextHub.Constants = ContextHub.Constants || {};
ContextHub.Constants.ANONYMOUS_HOME = "/home/users/5/5nQ6sQ_MOeL9fBsrnori";
ContextHub.Constants.MODE = "no-ui";
}());
</script><script src="/etc/cloudsettings.kernel.js/libs/settings/cloudsettings/legacy/contexthub" type="text/javascript"></script>
<script>
/* Start of MikMak tag */
(function(e,d){try{var a=window.swnDataLayer=window.swnDataLayer||{};a.appId=e||a.appId,a.eventBuffer=a.eventBuffer||[],a.loadBuffer=a.loadBuffer||[],a.push=a.push||function(e){a.eventBuffer.push(e)},a.load=a.load||function(e){a.loadBuffer.push(e)},a.dnt=a.dnt!=null?a.dnt:d;var t=document.getElementsByTagName("script")[0],n=document.createElement("script");n.async=!0,n.src="//wtb-tag.mikmak.ai/scripts/"+a.appId+"/tag.min.js",t.parentNode.insertBefore(n,t)}catch(e){console.log(e)}}("68cb4fc191899fdb207ce7a3", false));
/* End of MikMak tag */
</script>
<link rel="stylesheet" href="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-tyson-core.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-dependencies-buenamesa.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-site-buenamesa.lc-ba0804a2408c34972016bb159f46b1b6-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-base.lc-9222ec5da99d65c4c6fc2c8b9e4b4c77-lc.min.css" type="text/css">
<link rel="canonical" href="https://dev.buenamesa.com/"/>
<!-- meta -->
<meta charset="UTF-8"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-16x16.png" rel="icon" type="image/png" sizes="16x16"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-32x32.png" rel="icon" type="image/png" sizes="32x32"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/apple-touch-icon.png" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<link href="/themes/custom/tfs/favicons/apple-touch-icon.png?v=XS8BSoObZc" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<meta name="image" content="/content/dam/buenamesa/logos/hero-image-3.jpg"/>
<meta name="language-code" content="en"/>
<meta class="swiftype" name="page_id" data-type="string" content="1001807632"/>
<!--// meta -->
<script type="text/javascript" src="//assets.adobedtm.com/4b84b345350f/d08e96ac7cf8/launch-892d9bb32fe7-development.min.js" async></script>
<script src="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-t