GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa36cf963618065a7a325d305e2e28b57cce28b57cc
GraphQL introspection enabled at /graphql Types: 408 (by kind: ENUM: 2, INTERFACE: 7, OBJECT: 289, SCALAR: 7, UNION: 103) Operations: - Query: Query | fields: collection, collections, entries, entry, ping Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31870399cce601fa045b1eb61d0d99b49d0d99b49
GraphQL introspection enabled at /graphql Types: 395 (by kind: ENUM: 2, INTERFACE: 7, OBJECT: 276, SCALAR: 7, UNION: 103) Operations: - Query: Query | fields: collection, collections, entries, entry, ping Directives: deprecated, include, oneOf, skip (total: 4)
Open service 23.53.42.250:443 · staging-cms.ype.ind.br
2026-01-09 08:44
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Permissions-Policy: autoplay=(self), camera=(), encrypted-media=(self), fullscreen=(), geolocation=(self), gyroscope=(self), magnetometer=(), microphone=(), midi=(), payment=(), sync-xhr=(self), usb=()
Referrer-Policy: no-referrer-when-downgrade
X-XSS-Protection: 1; mode=block
Content-Security-Policy: default-src 'self'; script-src 'self' https://esm.sh https://unpkg.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://use.typekit.net https://cdn.jsdelivr.net 'unsafe-inline' 'unsafe-eval' data:; style-src 'self' 'unsafe-inline' https://esm.sh https://unpkg.com https://use.typekit.net https://cdn.jsdelivr.net; img-src 'self' https://p.typekit.net * data:; font-src 'self' https://use.typekit.net data: ; connect-src 'self' https://performance.typekit.net; media-src 'self'; frame-src 'self' https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://ype.ind.br/ https://www.ype.ind.br/ *.youtube.com *.vimeo.com *.calendly.com; object-src 'none'; base-uri 'self';
Expect-CT: enforce, max-age=30
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Cache-Control: private, no-cache
Date: Fri, 09 Jan 2026 08:44:43 GMT
Content-Length: 1413
Connection: close
X-XSS-Protection: 1; mode=block
X-Content-Type: Nosniff
Strict-Transport-Security: max-age=15768000 ; includeSubDomains
Page title: STAGING CMS - Ypê
<!doctype html>
<html lang="pt-BR">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>STAGING CMS - Ypê</title>
<link rel="icon" type="image/png" href="/favicon.svg" sizes="32x32" />
<link rel="icon" type="image/png" href="/favicon.svg" sizes="16x16" />
<!-- Fonts -->
<link href="https://fonts.googleapis.com/css?family=Nunito:200,600" rel="stylesheet" type="text/css">
<!-- Styles -->
<style>
html,
body {
background-color: #fff;
color: #636b6f;
font-family: 'Nunito', sans-serif;
font-weight: 200;
height: 100vh;
margin: 0;
}
.full-height {
height: 100vh;
}
.flex-center {
align-items: center;
display: flex;
justify-content: center;
}
.position-ref {
position: relative;
}
.content {
text-align: center;
}
.title {
font-size: 84px;
}
.m-b-md {
margin-bottom: 30px;
}
</style>
</head>
<body>
<div class="flex-center position-ref full-height">
<div class="content">
<div class="title m-b-md">
STAGING CMS - Ypê
</div>
</div>
</div>
</body>
</html>
Open service 2a02:26f0:ab00::214:8f61:80 · staging-cms.ype.ind.br
2026-01-05 14:07
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://staging-cms.ype.ind.br/ Cache-Control: max-age=0 Date: Mon, 05 Jan 2026 14:07:56 GMT Connection: close X-XSS-Protection: 1; mode=block X-Content-Type: Nosniff X-Frame-Options: SAMEORIGIN
Open service 2a02:26f0:ab00::214:8e30:80 · staging-cms.ype.ind.br
2026-01-05 14:07
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://staging-cms.ype.ind.br/ Cache-Control: max-age=0 Date: Mon, 05 Jan 2026 14:07:55 GMT Connection: close X-XSS-Protection: 1; mode=block X-Content-Type: Nosniff X-Frame-Options: SAMEORIGIN
Open service 2.16.183.15:443 · staging-cms.ype.ind.br
2026-01-05 14:07
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Permissions-Policy: autoplay=(self), camera=(), encrypted-media=(self), fullscreen=(), geolocation=(self), gyroscope=(self), magnetometer=(), microphone=(), midi=(), payment=(), sync-xhr=(self), usb=()
Referrer-Policy: no-referrer-when-downgrade
X-XSS-Protection: 1; mode=block
Content-Security-Policy: default-src 'self'; script-src 'self' https://esm.sh https://unpkg.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://use.typekit.net https://cdn.jsdelivr.net 'unsafe-inline' 'unsafe-eval' data:; style-src 'self' 'unsafe-inline' https://esm.sh https://unpkg.com https://use.typekit.net https://cdn.jsdelivr.net; img-src 'self' https://p.typekit.net * data:; font-src 'self' https://use.typekit.net data: ; connect-src 'self' https://performance.typekit.net; media-src 'self'; frame-src 'self' https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://ype.ind.br/ https://www.ype.ind.br/ *.youtube.com *.vimeo.com *.calendly.com; object-src 'none'; base-uri 'self';
Expect-CT: enforce, max-age=30
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Cache-Control: private, no-cache
Date: Mon, 05 Jan 2026 14:07:53 GMT
Content-Length: 1413
Connection: close
X-XSS-Protection: 1; mode=block
X-Content-Type: Nosniff
Strict-Transport-Security: max-age=15768000 ; includeSubDomains
Page title: STAGING CMS - Ypê
<!doctype html>
<html lang="pt-BR">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>STAGING CMS - Ypê</title>
<link rel="icon" type="image/png" href="/favicon.svg" sizes="32x32" />
<link rel="icon" type="image/png" href="/favicon.svg" sizes="16x16" />
<!-- Fonts -->
<link href="https://fonts.googleapis.com/css?family=Nunito:200,600" rel="stylesheet" type="text/css">
<!-- Styles -->
<style>
html,
body {
background-color: #fff;
color: #636b6f;
font-family: 'Nunito', sans-serif;
font-weight: 200;
height: 100vh;
margin: 0;
}
.full-height {
height: 100vh;
}
.flex-center {
align-items: center;
display: flex;
justify-content: center;
}
.position-ref {
position: relative;
}
.content {
text-align: center;
}
.title {
font-size: 84px;
}
.m-b-md {
margin-bottom: 30px;
}
</style>
</head>
<body>
<div class="flex-center position-ref full-height">
<div class="content">
<div class="title m-b-md">
STAGING CMS - Ypê
</div>
</div>
</div>
</body>
</html>
Open service 2a02:26f0:ab00::214:8e30:443 · staging-cms.ype.ind.br
2026-01-05 14:07
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Permissions-Policy: autoplay=(self), camera=(), encrypted-media=(self), fullscreen=(), geolocation=(self), gyroscope=(self), magnetometer=(), microphone=(), midi=(), payment=(), sync-xhr=(self), usb=()
Referrer-Policy: no-referrer-when-downgrade
X-XSS-Protection: 1; mode=block
Content-Security-Policy: default-src 'self'; script-src 'self' https://esm.sh https://unpkg.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://use.typekit.net https://cdn.jsdelivr.net 'unsafe-inline' 'unsafe-eval' data:; style-src 'self' 'unsafe-inline' https://esm.sh https://unpkg.com https://use.typekit.net https://cdn.jsdelivr.net; img-src 'self' https://p.typekit.net * data:; font-src 'self' https://use.typekit.net data: ; connect-src 'self' https://performance.typekit.net; media-src 'self'; frame-src 'self' https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://ype.ind.br/ https://www.ype.ind.br/ *.youtube.com *.vimeo.com *.calendly.com; object-src 'none'; base-uri 'self';
Expect-CT: enforce, max-age=30
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Cache-Control: private, no-cache
Date: Mon, 05 Jan 2026 14:07:53 GMT
Content-Length: 1413
Connection: close
X-XSS-Protection: 1; mode=block
X-Content-Type: Nosniff
Strict-Transport-Security: max-age=15768000 ; includeSubDomains
Page title: STAGING CMS - Ypê
<!doctype html>
<html lang="pt-BR">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>STAGING CMS - Ypê</title>
<link rel="icon" type="image/png" href="/favicon.svg" sizes="32x32" />
<link rel="icon" type="image/png" href="/favicon.svg" sizes="16x16" />
<!-- Fonts -->
<link href="https://fonts.googleapis.com/css?family=Nunito:200,600" rel="stylesheet" type="text/css">
<!-- Styles -->
<style>
html,
body {
background-color: #fff;
color: #636b6f;
font-family: 'Nunito', sans-serif;
font-weight: 200;
height: 100vh;
margin: 0;
}
.full-height {
height: 100vh;
}
.flex-center {
align-items: center;
display: flex;
justify-content: center;
}
.position-ref {
position: relative;
}
.content {
text-align: center;
}
.title {
font-size: 84px;
}
.m-b-md {
margin-bottom: 30px;
}
</style>
</head>
<body>
<div class="flex-center position-ref full-height">
<div class="content">
<div class="title m-b-md">
STAGING CMS - Ypê
</div>
</div>
</div>
</body>
</html>
Open service 2.16.183.16:80 · staging-cms.ype.ind.br
2026-01-05 14:07
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://staging-cms.ype.ind.br/ Cache-Control: max-age=0 Date: Mon, 05 Jan 2026 14:07:55 GMT Connection: close X-XSS-Protection: 1; mode=block X-Content-Type: Nosniff X-Frame-Options: SAMEORIGIN
Open service 2a02:26f0:ab00::214:8f61:443 · staging-cms.ype.ind.br
2026-01-05 14:07
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Permissions-Policy: autoplay=(self), camera=(), encrypted-media=(self), fullscreen=(), geolocation=(self), gyroscope=(self), magnetometer=(), microphone=(), midi=(), payment=(), sync-xhr=(self), usb=()
Referrer-Policy: no-referrer-when-downgrade
X-XSS-Protection: 1; mode=block
Content-Security-Policy: default-src 'self'; script-src 'self' https://esm.sh https://unpkg.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://use.typekit.net https://cdn.jsdelivr.net 'unsafe-inline' 'unsafe-eval' data:; style-src 'self' 'unsafe-inline' https://esm.sh https://unpkg.com https://use.typekit.net https://cdn.jsdelivr.net; img-src 'self' https://p.typekit.net * data:; font-src 'self' https://use.typekit.net data: ; connect-src 'self' https://performance.typekit.net; media-src 'self'; frame-src 'self' https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://ype.ind.br/ https://www.ype.ind.br/ *.youtube.com *.vimeo.com *.calendly.com; object-src 'none'; base-uri 'self';
Expect-CT: enforce, max-age=30
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Cache-Control: private, no-cache
Date: Mon, 05 Jan 2026 14:07:53 GMT
Content-Length: 1413
Connection: close
X-XSS-Protection: 1; mode=block
X-Content-Type: Nosniff
Strict-Transport-Security: max-age=15768000 ; includeSubDomains
Page title: STAGING CMS - Ypê
<!doctype html>
<html lang="pt-BR">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>STAGING CMS - Ypê</title>
<link rel="icon" type="image/png" href="/favicon.svg" sizes="32x32" />
<link rel="icon" type="image/png" href="/favicon.svg" sizes="16x16" />
<!-- Fonts -->
<link href="https://fonts.googleapis.com/css?family=Nunito:200,600" rel="stylesheet" type="text/css">
<!-- Styles -->
<style>
html,
body {
background-color: #fff;
color: #636b6f;
font-family: 'Nunito', sans-serif;
font-weight: 200;
height: 100vh;
margin: 0;
}
.full-height {
height: 100vh;
}
.flex-center {
align-items: center;
display: flex;
justify-content: center;
}
.position-ref {
position: relative;
}
.content {
text-align: center;
}
.title {
font-size: 84px;
}
.m-b-md {
margin-bottom: 30px;
}
</style>
</head>
<body>
<div class="flex-center position-ref full-height">
<div class="content">
<div class="title m-b-md">
STAGING CMS - Ypê
</div>
</div>
</div>
</body>
</html>
Open service 2.16.183.15:80 · staging-cms.ype.ind.br
2026-01-05 14:07
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://staging-cms.ype.ind.br/ Cache-Control: max-age=0 Date: Mon, 05 Jan 2026 14:07:55 GMT Connection: close X-XSS-Protection: 1; mode=block X-Content-Type: Nosniff X-Frame-Options: SAMEORIGIN
Open service 23.53.42.250:443 · staging-cms.ype.ind.br
2026-01-02 08:40
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Permissions-Policy: autoplay=(self), camera=(), encrypted-media=(self), fullscreen=(), geolocation=(self), gyroscope=(self), magnetometer=(), microphone=(), midi=(), payment=(), sync-xhr=(self), usb=()
Referrer-Policy: no-referrer-when-downgrade
X-XSS-Protection: 1; mode=block
Content-Security-Policy: default-src 'self'; script-src 'self' https://esm.sh https://unpkg.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://use.typekit.net https://cdn.jsdelivr.net 'unsafe-inline' 'unsafe-eval' data:; style-src 'self' 'unsafe-inline' https://esm.sh https://unpkg.com https://use.typekit.net https://cdn.jsdelivr.net; img-src 'self' https://p.typekit.net * data:; font-src 'self' https://use.typekit.net data: ; connect-src 'self' https://performance.typekit.net; media-src 'self'; frame-src 'self' https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://ype.ind.br/ https://www.ype.ind.br/ *.youtube.com *.vimeo.com *.calendly.com; object-src 'none'; base-uri 'self';
Expect-CT: enforce, max-age=30
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Cache-Control: private, no-cache
Date: Fri, 02 Jan 2026 08:40:54 GMT
Content-Length: 1413
Connection: close
X-XSS-Protection: 1; mode=block
X-Content-Type: Nosniff
Strict-Transport-Security: max-age=15768000 ; includeSubDomains
Page title: STAGING CMS - Ypê
<!doctype html>
<html lang="pt-BR">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>STAGING CMS - Ypê</title>
<link rel="icon" type="image/png" href="/favicon.svg" sizes="32x32" />
<link rel="icon" type="image/png" href="/favicon.svg" sizes="16x16" />
<!-- Fonts -->
<link href="https://fonts.googleapis.com/css?family=Nunito:200,600" rel="stylesheet" type="text/css">
<!-- Styles -->
<style>
html,
body {
background-color: #fff;
color: #636b6f;
font-family: 'Nunito', sans-serif;
font-weight: 200;
height: 100vh;
margin: 0;
}
.full-height {
height: 100vh;
}
.flex-center {
align-items: center;
display: flex;
justify-content: center;
}
.position-ref {
position: relative;
}
.content {
text-align: center;
}
.title {
font-size: 84px;
}
.m-b-md {
margin-bottom: 30px;
}
</style>
</head>
<body>
<div class="flex-center position-ref full-height">
<div class="content">
<div class="title m-b-md">
STAGING CMS - Ypê
</div>
</div>
</div>
</body>
</html>
Open service 23.53.42.250:443 · staging-cms.ype.ind.br
2025-12-22 22:53
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Permissions-Policy: autoplay=(self), camera=(), encrypted-media=(self), fullscreen=(), geolocation=(self), gyroscope=(self), magnetometer=(), microphone=(), midi=(), payment=(), sync-xhr=(self), usb=()
Referrer-Policy: no-referrer-when-downgrade
X-XSS-Protection: 1; mode=block
Content-Security-Policy: default-src 'self'; script-src 'self' https://esm.sh https://unpkg.com https://www.google.com/recaptcha/ https://www.gstatic.com/recaptcha/ https://use.typekit.net https://cdn.jsdelivr.net 'unsafe-inline' 'unsafe-eval' data:; style-src 'self' 'unsafe-inline' https://esm.sh https://unpkg.com https://use.typekit.net https://cdn.jsdelivr.net; img-src 'self' https://p.typekit.net * data:; font-src 'self' https://use.typekit.net data: ; connect-src 'self' https://performance.typekit.net; media-src 'self'; frame-src 'self' https://www.google.com/recaptcha/ https://recaptcha.google.com/recaptcha/ https://ype.ind.br/ https://www.ype.ind.br/ *.youtube.com *.vimeo.com *.calendly.com; object-src 'none'; base-uri 'self';
Expect-CT: enforce, max-age=30
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Cache-Control: private, no-cache
Date: Mon, 22 Dec 2025 22:53:43 GMT
Content-Length: 1413
Connection: close
X-XSS-Protection: 1; mode=block
X-Content-Type: Nosniff
Strict-Transport-Security: max-age=15768000 ; includeSubDomains
Page title: STAGING CMS - Ypê
<!doctype html>
<html lang="pt-BR">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>STAGING CMS - Ypê</title>
<link rel="icon" type="image/png" href="/favicon.svg" sizes="32x32" />
<link rel="icon" type="image/png" href="/favicon.svg" sizes="16x16" />
<!-- Fonts -->
<link href="https://fonts.googleapis.com/css?family=Nunito:200,600" rel="stylesheet" type="text/css">
<!-- Styles -->
<style>
html,
body {
background-color: #fff;
color: #636b6f;
font-family: 'Nunito', sans-serif;
font-weight: 200;
height: 100vh;
margin: 0;
}
.full-height {
height: 100vh;
}
.flex-center {
align-items: center;
display: flex;
justify-content: center;
}
.position-ref {
position: relative;
}
.content {
text-align: center;
}
.title {
font-size: 84px;
}
.m-b-md {
margin-bottom: 30px;
}
</style>
</head>
<body>
<div class="flex-center position-ref full-height">
<div class="content">
<div class="title m-b-md">
STAGING CMS - Ypê
</div>
</div>
</div>
</body>
</html>