GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa384f1b85148b4fa93157b58fcb82c6099104d49fc
GraphQL introspection enabled at /graphql Types: 628 (by kind: ENUM: 46, INPUT_OBJECT: 149, INTERFACE: 28, OBJECT: 395, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, skip (total: 3) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2dbb5e0b0029887341363718760c0d0301c654c3f
GraphQL introspection enabled at /graphql/api Types: 628 (by kind: ENUM: 46, INPUT_OBJECT: 149, INTERFACE: 28, OBJECT: 395, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, skip (total: 3) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa384f1b85148b4fa93157b58fcb82c609907f9dba9
GraphQL introspection enabled at /graphql Types: 628 (by kind: ENUM: 46, INPUT_OBJECT: 149, INTERFACE: 28, OBJECT: 395, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2dbb5e0b0029887341363718760c0d0305f9cfea8
GraphQL introspection enabled at /graphql/api Types: 628 (by kind: ENUM: 46, INPUT_OBJECT: 149, INTERFACE: 28, OBJECT: 395, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa384f1b85148b4fa93157b58fcb82c6099104d49fc
GraphQL introspection enabled at /graphql Types: 628 (by kind: ENUM: 46, INPUT_OBJECT: 149, INTERFACE: 28, OBJECT: 395, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, skip (total: 3) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2dbb5e0b0029887341363718760c0d0301c654c3f
GraphQL introspection enabled at /graphql/api Types: 628 (by kind: ENUM: 46, INPUT_OBJECT: 149, INTERFACE: 28, OBJECT: 395, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, skip (total: 3) Detected: Magento
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2dbb5e0b0029887341363718760c0d0301c654c3f
GraphQL introspection enabled at /graphql/api Types: 628 (by kind: ENUM: 46, INPUT_OBJECT: 149, INTERFACE: 28, OBJECT: 395, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, skip (total: 3) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa384f1b85148b4fa93157b58fcb82c6099104d49fc
GraphQL introspection enabled at /graphql Types: 628 (by kind: ENUM: 46, INPUT_OBJECT: 149, INTERFACE: 28, OBJECT: 395, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, skip (total: 3) Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa384f1b85148b4fa93157b58fcb82c609907f9dba9
GraphQL introspection enabled at /graphql Types: 628 (by kind: ENUM: 46, INPUT_OBJECT: 149, INTERFACE: 28, OBJECT: 395, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2dbb5e0b0029887341363718760c0d0305f9cfea8
GraphQL introspection enabled at /graphql/api Types: 628 (by kind: ENUM: 46, INPUT_OBJECT: 149, INTERFACE: 28, OBJECT: 395, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2f8cbe7e2
GraphQL introspection enabled at /graphql/api
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa374c2942e74c2942e74c2942e74c2942e74c2942e
GraphQL introspection enabled at /graphql Detected: Magento
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa384f1b85148b4fa93157b58fcb82c609907f9dba9
GraphQL introspection enabled at /graphql Types: 628 (by kind: ENUM: 46, INPUT_OBJECT: 149, INTERFACE: 28, OBJECT: 395, SCALAR: 5, UNION: 5) Operations: - Query: Query | fields: availableStores, cart, categories, category, categoryList - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, skip (total: 3)
Open service 18.217.133.29:443 · api.current.waterworks.com
2026-01-23 16:05
HTTP/1.1 301 Moved Permanently Date: Fri, 23 Jan 2026 16:05:28 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=8fac64be7e468e34ad4a77de0a29e9a9; expires=Sat, 24-Jan-2026 16:05:28 GMT; Max-Age=86400; path=/; domain=current.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://current.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:443 · dev.static.waterworks.com
2026-01-23 09:57
HTTP/1.1 301 Moved Permanently Date: Fri, 23 Jan 2026 09:57:54 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=35d2cda0713190a888e1756f22399e07; expires=Sat, 24-Jan-2026 09:57:54 GMT; Max-Age=86400; path=/; domain=dev.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://dev.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:443 · api.dev.waterworks.com
2026-01-23 05:01
HTTP/1.1 301 Moved Permanently Date: Fri, 23 Jan 2026 05:01:42 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=e6af0b5c1dcd1f095f255a62281b26d2; expires=Sat, 24-Jan-2026 05:01:41 GMT; Max-Age=86400; path=/; domain=dev.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://dev.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:443 · current.static.waterworks.com
2026-01-22 23:11
HTTP/1.1 301 Moved Permanently Date: Thu, 22 Jan 2026 23:11:58 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=9f3b24d716881e8c7233d88e70096c70; expires=Fri, 23-Jan-2026 23:11:58 GMT; Max-Age=86400; path=/; domain=current.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://current.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:443 · api.current.waterworks.com
2026-01-09 20:39
HTTP/1.1 301 Moved Permanently Date: Fri, 09 Jan 2026 20:40:02 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=134e40e44dd7cd4f2bc8a04d8822145d; expires=Sat, 10-Jan-2026 20:40:02 GMT; Max-Age=86400; path=/; domain=current.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://current.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:443 · api.dev.waterworks.com
2026-01-09 17:17
HTTP/1.1 301 Moved Permanently Date: Fri, 09 Jan 2026 17:17:20 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=a9e6c7f208faa74cf497e8817c8581d8; expires=Sat, 10-Jan-2026 17:17:20 GMT; Max-Age=86400; path=/; domain=dev.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://dev.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:443 · dev.static.waterworks.com
2026-01-09 12:44
HTTP/1.1 301 Moved Permanently Date: Fri, 09 Jan 2026 12:44:11 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=856ec14f143d8573711c3f33382b6a20; expires=Sat, 10-Jan-2026 12:44:11 GMT; Max-Age=86400; path=/; domain=dev.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://dev.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:443 · current.static.waterworks.com
2026-01-08 19:10
HTTP/1.1 301 Moved Permanently Date: Thu, 08 Jan 2026 19:10:53 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=b195bdc689f537767df2c8d3f3708c4e; expires=Fri, 09-Jan-2026 19:10:53 GMT; Max-Age=86400; path=/; domain=current.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://current.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:443 · dev.static.waterworks.com
2026-01-02 20:16
HTTP/1.1 301 Moved Permanently Date: Fri, 02 Jan 2026 20:16:35 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=b173fa54e02729c58194e944ccc50f65; expires=Sat, 03-Jan-2026 20:16:35 GMT; Max-Age=86400; path=/; domain=dev.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://dev.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:443 · api.dev.waterworks.com
2026-01-02 17:32
HTTP/1.1 301 Moved Permanently Date: Fri, 02 Jan 2026 17:32:54 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=a38ccddc8ccc1d628b53fd5e99d944e1; expires=Sat, 03-Jan-2026 17:32:54 GMT; Max-Age=86400; path=/; domain=dev.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://dev.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:80 · api.current.waterworks.com
2026-01-02 17:03
HTTP/1.1 308 Permanent Redirect Date: Fri, 02 Jan 2026 17:03:08 GMT Content-Type: text/html Content-Length: 164 Connection: close Location: https://api.current.waterworks.com Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 18.217.133.29:443 · api.current.waterworks.com
2026-01-02 17:03
HTTP/1.1 301 Moved Permanently Date: Fri, 02 Jan 2026 17:03:09 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=7b608fd50196e73fcfa1f83ec8033536; expires=Sat, 03-Jan-2026 17:03:09 GMT; Max-Age=86400; path=/; domain=current.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://current.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:443 · api.current.waterworks.com
2026-01-02 12:36
HTTP/1.1 301 Moved Permanently Date: Fri, 02 Jan 2026 12:36:49 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=b93ebfb67b5102d44d29e375f3cd8f07; expires=Sat, 03-Jan-2026 12:36:49 GMT; Max-Age=86400; path=/; domain=current.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://current.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:443 · api.stg.waterworks.com
2025-12-31 08:49
HTTP/1.1 403 Forbidden Date: Wed, 31 Dec 2025 08:49:40 GMT Content-Type: text/html Content-Length: 146 Connection: close Strict-Transport-Security: max-age=31536000; includeSubDomains Page title: 403 Forbidden <html> <head><title>403 Forbidden</title></head> <body> <center><h1>403 Forbidden</h1></center> <hr><center>nginx</center> </body> </html>
Open service 18.217.133.29:80 · api.stg.waterworks.com
2025-12-31 08:49
HTTP/1.1 308 Permanent Redirect Date: Wed, 31 Dec 2025 08:49:40 GMT Content-Type: text/html Content-Length: 164 Connection: close Location: https://api.stg.waterworks.com Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 18.217.133.29:443 · api.dev.waterworks.com
2025-12-23 00:00
HTTP/1.1 301 Moved Permanently Date: Tue, 23 Dec 2025 00:00:25 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=08ef680efa616c4b3c17b59a50de716b; expires=Wed, 24-Dec-2025 00:00:25 GMT; Max-Age=86400; path=/; domain=dev.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://dev.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains
Open service 18.217.133.29:443 · api.current.waterworks.com
2025-12-22 10:58
HTTP/1.1 301 Moved Permanently Date: Mon, 22 Dec 2025 10:58:00 GMT Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close X-Powered-By: PHP/8.1.33 Set-Cookie: PHPSESSID=ff21d9ebe58bba6ff44ec9a406a266e7; expires=Tue, 23-Dec-2025 10:58:00 GMT; Max-Age=86400; path=/; domain=current.waterworks.com; secure; HttpOnly; SameSite=Lax Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Location: https://current.waterworks.com/us_en/ Access-Control-Allow-Origin: *.waterworks.com Strict-Transport-Security: max-age=31536000; includeSubDomains