GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6d5e6ea65d5e6ea65d5e6ea65d5e6ea65d5e6ea65
GraphQL introspection enabled at /api/graphql Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d60479c685c36ad747762d0ab155eafb05dab91a01
GraphQL introspection enabled at /api/graphql Types: 435 (by kind: ENUM: 27, INPUT_OBJECT: 101, INTERFACE: 18, OBJECT: 284, SCALAR: 5) Operations: - Query: Query | fields: categories, category, categoryList, customAttributeMetadata, products Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 categories (args: optional/default) : total_count=7 products (args: optional/default) : total_count=1136
Open service 151.101.131.10:80 · stage.buenamesa.com
2026-01-27 15:32
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 Retry-After: 0 Location: https://stage.buenamesa.com/ Accept-Ranges: bytes Date: Tue, 27 Jan 2026 15:32:04 GMT Strict-Transport-Security: max-age=31557600 X-Served-By: cache-lga21960-LGA X-Cache: HIT X-Timer: S1769527925.681331,VS0,VE2
Open service 151.101.131.10:443 · stage.buenamesa.com
2026-01-22 23:28
HTTP/1.1 200 OK
Connection: close
Content-Length: 44238
x-frame-options: SAMEORIGIN
cache-control: max-age=300,stale-while-revalidate=300
x-frame-options: SAMEORIGIN
last-modified: Thu, 22 Jan 2026 23:28:40 GMT
etag: W/"acce-6490266a2f77d"
x-vhost: buenamesa.com
content-type: text/html;charset=utf-8
X-Content-Type-Options: nosniff
Accept-Ranges: bytes
Age: 0
Date: Thu, 22 Jan 2026 23:28:41 GMT
Strict-Transport-Security: max-age=31557600
set-cookie: affinity="c9057c0ecfac9e20"; Path=/; HttpOnly; secure
X-Served-By: cache-fra-eddf8230056-FRA
X-Cache: MISS
X-Timer: S1769124519.393778,VS0,VS0,VE1827
Vary: Accept-Encoding
Page title: Buena Mesa Home
<!DOCTYPE HTML>
<html lang="en">
<head>
<head>
<title class="mainPageTitle">Buena Mesa Home</title>
</head>
<meta class="pageDesc" name="description" content="buena mesa"/>
<meta name="template" content="buenamesa-freeform-template"/>
<meta name="viewport" content="width=device-width, initial-scale=1"/>
<script defer="defer" type="text/javascript" src="/.rum/@adobe/helix-rum-js@%5E2/dist/rum-standalone.js"></script>
<script src="https://kit.fontawesome.com/136d59004e.js" crossorigin="anonymous" defer></script>
<script src="https://www.youtube.com/iframe_api"></script>
<script type="text/javascript">
(function() {
window.ContextHub = window.ContextHub || {};
/* setting paths */
ContextHub.Paths = ContextHub.Paths || {};
ContextHub.Paths.CONTEXTHUB_PATH = "/libs/settings/cloudsettings/legacy/contexthub";
ContextHub.Paths.RESOURCE_PATH = "\/content\/buenamesa\/us\/en\/_jcr_content\/contexthub";
ContextHub.Paths.SEGMENTATION_PATH = "";
ContextHub.Paths.CQ_CONTEXT_PATH = "";
/* setting initial constants */
ContextHub.Constants = ContextHub.Constants || {};
ContextHub.Constants.ANONYMOUS_HOME = "/home/users/b/b1f-42DSUnVkS3cCqILI";
ContextHub.Constants.MODE = "no-ui";
}());
</script><script src="/etc/cloudsettings.kernel.js/libs/settings/cloudsettings/legacy/contexthub" type="text/javascript"></script>
<script>
/* Start of MikMak tag */
(function(e,d){try{var a=window.swnDataLayer=window.swnDataLayer||{};a.appId=e||a.appId,a.eventBuffer=a.eventBuffer||[],a.loadBuffer=a.loadBuffer||[],a.push=a.push||function(e){a.eventBuffer.push(e)},a.load=a.load||function(e){a.loadBuffer.push(e)},a.dnt=a.dnt!=null?a.dnt:d;var t=document.getElementsByTagName("script")[0],n=document.createElement("script");n.async=!0,n.src="//wtb-tag.mikmak.ai/scripts/"+a.appId+"/tag.min.js",t.parentNode.insertBefore(n,t)}catch(e){console.log(e)}}("68cb4fc191899fdb207ce7a3", false));
/* End of MikMak tag */
</script>
<link rel="stylesheet" href="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-tyson-core.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-dependencies-buenamesa.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-site-buenamesa.lc-2625c9ceabeb419b7e3d6345c739c6ed-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-base.lc-9222ec5da99d65c4c6fc2c8b9e4b4c77-lc.min.css" type="text/css">
<link rel="canonical" href="https://stage.buenamesa.com/"/>
<!-- meta -->
<meta charset="UTF-8"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-16x16.png" rel="icon" type="image/png" sizes="16x16"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-32x32.png" rel="icon" type="image/png" sizes="32x32"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/apple-touch-icon.png" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<link href="/themes/custom/tfs/favicons/apple-touch-icon.png?v=XS8BSoObZc" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<meta name="image" content="/content/dam/buenamesa/logos/hero-image-3.jpg"/>
<meta name="language-code" content="en"/>
<meta class="swiftype" name="page_id" data-type="string" content="1001807632"/>
<!--// meta -->
<script type="text/javascript" src="//assets.adobedtm.com/4b84b345350f/d08e96ac7cf8/launch-edbb73fb5297-staging.min.js" async></script>
<script src="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-tys
Open service 151.101.131.10:443 · stage.buenamesa.com
2026-01-09 01:56
HTTP/1.1 200 OK
Connection: close
Content-Length: 44238
x-frame-options: SAMEORIGIN
cache-control: max-age=300,stale-while-revalidate=300
x-frame-options: SAMEORIGIN
last-modified: Thu, 08 Jan 2026 20:40:23 GMT
etag: "acce-647e66b02018f"
x-vhost: buenamesa.com
content-type: text/html;charset=utf-8
X-Content-Type-Options: nosniff
Accept-Ranges: bytes
Age: 0
Date: Fri, 09 Jan 2026 01:56:19 GMT
Strict-Transport-Security: max-age=31557600
set-cookie: affinity="ad0885750a004693"; Path=/; HttpOnly; secure
X-Served-By: cache-vie6339-VIE
X-Cache: MISS
X-Timer: S1767923779.598403,VS0,VS0,VE752
Vary: Accept-Encoding
Page title: Buena Mesa Home
<!DOCTYPE HTML>
<html lang="en">
<head>
<head>
<title class="mainPageTitle">Buena Mesa Home</title>
</head>
<meta class="pageDesc" name="description" content="buena mesa"/>
<meta name="template" content="buenamesa-freeform-template"/>
<meta name="viewport" content="width=device-width, initial-scale=1"/>
<script defer="defer" type="text/javascript" src="/.rum/@adobe/helix-rum-js@%5E2/dist/rum-standalone.js"></script>
<script src="https://kit.fontawesome.com/136d59004e.js" crossorigin="anonymous" defer></script>
<script src="https://www.youtube.com/iframe_api"></script>
<script type="text/javascript">
(function() {
window.ContextHub = window.ContextHub || {};
/* setting paths */
ContextHub.Paths = ContextHub.Paths || {};
ContextHub.Paths.CONTEXTHUB_PATH = "/libs/settings/cloudsettings/legacy/contexthub";
ContextHub.Paths.RESOURCE_PATH = "\/content\/buenamesa\/us\/en\/_jcr_content\/contexthub";
ContextHub.Paths.SEGMENTATION_PATH = "";
ContextHub.Paths.CQ_CONTEXT_PATH = "";
/* setting initial constants */
ContextHub.Constants = ContextHub.Constants || {};
ContextHub.Constants.ANONYMOUS_HOME = "/home/users/b/b1f-42DSUnVkS3cCqILI";
ContextHub.Constants.MODE = "no-ui";
}());
</script><script src="/etc/cloudsettings.kernel.js/libs/settings/cloudsettings/legacy/contexthub" type="text/javascript"></script>
<script>
/* Start of MikMak tag */
(function(e,d){try{var a=window.swnDataLayer=window.swnDataLayer||{};a.appId=e||a.appId,a.eventBuffer=a.eventBuffer||[],a.loadBuffer=a.loadBuffer||[],a.push=a.push||function(e){a.eventBuffer.push(e)},a.load=a.load||function(e){a.loadBuffer.push(e)},a.dnt=a.dnt!=null?a.dnt:d;var t=document.getElementsByTagName("script")[0],n=document.createElement("script");n.async=!0,n.src="//wtb-tag.mikmak.ai/scripts/"+a.appId+"/tag.min.js",t.parentNode.insertBefore(n,t)}catch(e){console.log(e)}}("68cb4fc191899fdb207ce7a3", false));
/* End of MikMak tag */
</script>
<link rel="stylesheet" href="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-tyson-core.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-dependencies-buenamesa.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-site-buenamesa.lc-2625c9ceabeb419b7e3d6345c739c6ed-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-base.lc-9222ec5da99d65c4c6fc2c8b9e4b4c77-lc.min.css" type="text/css">
<link rel="canonical" href="https://stage.buenamesa.com/"/>
<!-- meta -->
<meta charset="UTF-8"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-16x16.png" rel="icon" type="image/png" sizes="16x16"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-32x32.png" rel="icon" type="image/png" sizes="32x32"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/apple-touch-icon.png" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<link href="/themes/custom/tfs/favicons/apple-touch-icon.png?v=XS8BSoObZc" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<meta name="image" content="/content/dam/buenamesa/logos/hero-image-3.jpg"/>
<meta name="language-code" content="en"/>
<meta class="swiftype" name="page_id" data-type="string" content="1001807632"/>
<!--// meta -->
<script type="text/javascript" src="//assets.adobedtm.com/4b84b345350f/d08e96ac7cf8/launch-edbb73fb5297-staging.min.js" async></script>
<script src="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-tys
Open service 151.101.131.10:443 · stage.buenamesa.com
2026-01-01 19:41
HTTP/1.1 200 OK
Connection: close
Content-Length: 44238
x-frame-options: SAMEORIGIN
cache-control: max-age=300,stale-while-revalidate=300
x-frame-options: SAMEORIGIN
last-modified: Thu, 01 Jan 2026 11:07:03 GMT
etag: "acce-6475197b5a6e6"
x-vhost: buenamesa.com
content-type: text/html;charset=utf-8
X-Content-Type-Options: nosniff
Accept-Ranges: bytes
Age: 0
Date: Thu, 01 Jan 2026 19:41:53 GMT
Strict-Transport-Security: max-age=31557600
set-cookie: affinity="62de201968dd0f72"; Path=/; HttpOnly; secure
X-Served-By: cache-fra-eddf8230115-FRA
X-Cache: MISS
X-Timer: S1767296513.528727,VS0,VS0,VE542
Vary: Accept-Encoding
Page title: Buena Mesa Home
<!DOCTYPE HTML>
<html lang="en">
<head>
<head>
<title class="mainPageTitle">Buena Mesa Home</title>
</head>
<meta class="pageDesc" name="description" content="buena mesa"/>
<meta name="template" content="buenamesa-freeform-template"/>
<meta name="viewport" content="width=device-width, initial-scale=1"/>
<script defer="defer" type="text/javascript" src="/.rum/@adobe/helix-rum-js@%5E2/dist/rum-standalone.js"></script>
<script src="https://kit.fontawesome.com/136d59004e.js" crossorigin="anonymous" defer></script>
<script src="https://www.youtube.com/iframe_api"></script>
<script type="text/javascript">
(function() {
window.ContextHub = window.ContextHub || {};
/* setting paths */
ContextHub.Paths = ContextHub.Paths || {};
ContextHub.Paths.CONTEXTHUB_PATH = "/libs/settings/cloudsettings/legacy/contexthub";
ContextHub.Paths.RESOURCE_PATH = "\/content\/buenamesa\/us\/en\/_jcr_content\/contexthub";
ContextHub.Paths.SEGMENTATION_PATH = "";
ContextHub.Paths.CQ_CONTEXT_PATH = "";
/* setting initial constants */
ContextHub.Constants = ContextHub.Constants || {};
ContextHub.Constants.ANONYMOUS_HOME = "/home/users/b/b1f-42DSUnVkS3cCqILI";
ContextHub.Constants.MODE = "no-ui";
}());
</script><script src="/etc/cloudsettings.kernel.js/libs/settings/cloudsettings/legacy/contexthub" type="text/javascript"></script>
<script>
/* Start of MikMak tag */
(function(e,d){try{var a=window.swnDataLayer=window.swnDataLayer||{};a.appId=e||a.appId,a.eventBuffer=a.eventBuffer||[],a.loadBuffer=a.loadBuffer||[],a.push=a.push||function(e){a.eventBuffer.push(e)},a.load=a.load||function(e){a.loadBuffer.push(e)},a.dnt=a.dnt!=null?a.dnt:d;var t=document.getElementsByTagName("script")[0],n=document.createElement("script");n.async=!0,n.src="//wtb-tag.mikmak.ai/scripts/"+a.appId+"/tag.min.js",t.parentNode.insertBefore(n,t)}catch(e){console.log(e)}}("68cb4fc191899fdb207ce7a3", false));
/* End of MikMak tag */
</script>
<link rel="stylesheet" href="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-tyson-core.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-dependencies-buenamesa.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-site-buenamesa.lc-2625c9ceabeb419b7e3d6345c739c6ed-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-base.lc-9222ec5da99d65c4c6fc2c8b9e4b4c77-lc.min.css" type="text/css">
<link rel="canonical" href="https://stage.buenamesa.com/"/>
<!-- meta -->
<meta charset="UTF-8"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-16x16.png" rel="icon" type="image/png" sizes="16x16"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-32x32.png" rel="icon" type="image/png" sizes="32x32"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/apple-touch-icon.png" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<link href="/themes/custom/tfs/favicons/apple-touch-icon.png?v=XS8BSoObZc" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<meta name="image" content="/content/dam/buenamesa/logos/hero-image-3.jpg"/>
<meta name="language-code" content="en"/>
<meta class="swiftype" name="page_id" data-type="string" content="1001807632"/>
<!--// meta -->
<script type="text/javascript" src="//assets.adobedtm.com/4b84b345350f/d08e96ac7cf8/launch-edbb73fb5297-staging.min.js" async></script>
<script src="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-tys
Open service 151.101.131.10:443 · stage.buenamesa.com
2025-12-22 21:50
HTTP/1.1 200 OK
Connection: close
Content-Length: 44238
x-frame-options: SAMEORIGIN
cache-control: max-age=300,stale-while-revalidate=300
x-frame-options: SAMEORIGIN
last-modified: Mon, 22 Dec 2025 11:37:01 GMT
etag: "acce-64688d871e858"
x-vhost: buenamesa.com
content-type: text/html;charset=utf-8
X-Content-Type-Options: nosniff
Accept-Ranges: bytes
Date: Mon, 22 Dec 2025 21:50:54 GMT
Age: 0
Strict-Transport-Security: max-age=31557600
X-Served-By: cache-fra-eddf8230134-FRA
X-Cache: HIT
X-Timer: S1766440255.670719,VS0,VS0,VE3
Vary: Accept-Encoding
Page title: Buena Mesa Home
<!DOCTYPE HTML>
<html lang="en">
<head>
<head>
<title class="mainPageTitle">Buena Mesa Home</title>
</head>
<meta class="pageDesc" name="description" content="buena mesa"/>
<meta name="template" content="buenamesa-freeform-template"/>
<meta name="viewport" content="width=device-width, initial-scale=1"/>
<script defer="defer" type="text/javascript" src="/.rum/@adobe/helix-rum-js@%5E2/dist/rum-standalone.js"></script>
<script src="https://kit.fontawesome.com/136d59004e.js" crossorigin="anonymous" defer></script>
<script src="https://www.youtube.com/iframe_api"></script>
<script type="text/javascript">
(function() {
window.ContextHub = window.ContextHub || {};
/* setting paths */
ContextHub.Paths = ContextHub.Paths || {};
ContextHub.Paths.CONTEXTHUB_PATH = "/libs/settings/cloudsettings/legacy/contexthub";
ContextHub.Paths.RESOURCE_PATH = "\/content\/buenamesa\/us\/en\/_jcr_content\/contexthub";
ContextHub.Paths.SEGMENTATION_PATH = "";
ContextHub.Paths.CQ_CONTEXT_PATH = "";
/* setting initial constants */
ContextHub.Constants = ContextHub.Constants || {};
ContextHub.Constants.ANONYMOUS_HOME = "/home/users/b/b1f-42DSUnVkS3cCqILI";
ContextHub.Constants.MODE = "no-ui";
}());
</script><script src="/etc/cloudsettings.kernel.js/libs/settings/cloudsettings/legacy/contexthub" type="text/javascript"></script>
<script>
/* Start of MikMak tag */
(function(e,d){try{var a=window.swnDataLayer=window.swnDataLayer||{};a.appId=e||a.appId,a.eventBuffer=a.eventBuffer||[],a.loadBuffer=a.loadBuffer||[],a.push=a.push||function(e){a.eventBuffer.push(e)},a.load=a.load||function(e){a.loadBuffer.push(e)},a.dnt=a.dnt!=null?a.dnt:d;var t=document.getElementsByTagName("script")[0],n=document.createElement("script");n.async=!0,n.src="//wtb-tag.mikmak.ai/scripts/"+a.appId+"/tag.min.js",t.parentNode.insertBefore(n,t)}catch(e){console.log(e)}}("68cb4fc191899fdb207ce7a3", false));
/* End of MikMak tag */
</script>
<link rel="stylesheet" href="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-tyson-core.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-dependencies-buenamesa.lc-d41d8cd98f00b204e9800998ecf8427e-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-site-buenamesa.lc-2625c9ceabeb419b7e3d6345c739c6ed-lc.min.css" type="text/css">
<link rel="stylesheet" href="/etc.clientlibs/buenamesa/clientlibs/clientlib-base.lc-9222ec5da99d65c4c6fc2c8b9e4b4c77-lc.min.css" type="text/css">
<link rel="canonical" href="https://stage.buenamesa.com/"/>
<!-- meta -->
<meta charset="UTF-8"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-16x16.png" rel="icon" type="image/png" sizes="16x16"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/favicon-32x32.png" rel="icon" type="image/png" sizes="32x32"/>
<link href="/etc.clientlibs/retail/clientlibs/clientlib-site-retail/resources/images/apple-touch-icon.png" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<link href="/themes/custom/tfs/favicons/apple-touch-icon.png?v=XS8BSoObZc" rel="apple-touch-icon" type="image/png" sizes="180x180"/>
<meta name="image" content="/content/dam/buenamesa/logos/hero-image-3.jpg"/>
<meta name="language-code" content="en"/>
<meta class="swiftype" name="page_id" data-type="string" content="1001807632"/>
<!--// meta -->
<script type="text/javascript" src="//assets.adobedtm.com/4b84b345350f/d08e96ac7cf8/launch-edbb73fb5297-staging.min.js" async></script>
<script src="/etc.clientlibs/tyson-core/clientlibs/clientlib-dependencies-tys