Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035491da2c34d351e21362f8c821f0889d1fd2a899098
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /services/data/{apiVersion}/sobjects/MobilePushServiceDevice/{id}
GET /Asset/LindeSerialNumber
GET /Asset/Tools
GET /AssetScrappingReason
GET /HcUtilities/CheckVersion
GET /HcUtilities/UserProfile
GET /Job/GetJobByFoJobId/{foJobId}
GET /Job/GetJobNoSignedReasons
GET /Job/GetJobsByTechnician
GET /Material/KitSearch
GET /Material/Search
GET /MaterialPoint/AssetDefaultDestination
GET /MaterialPoint/Search
GET /Patient/GetPatientByFoPatientId/{foPatientId}
GET /RiskAssessment
GET /RiskAssessment/{riskAssessmentId}
GET /WorkshopActivity
GET /WorkshopActivity/SparePartExchangeReason
GET /WorkshopActivity/SpareParts
GET /WorkshopActivity/Tools
GET /WorkshopActivityType
GET /api/Values
GET /api/Values/{id}
GET /asset/activeassets
GET /document
GET /document/Index
GET /notifications/registration/GetAll
GET /services/apexrest/MobileVizArt/countryTranslations
GET /services/apexrest/MobileVizArt/getCountrySettingnew/{countryName}
GET /services/apexrest/MobileVizArt/getTripJobsCount
GET /services/apexrest/MobileVizArt/getUserInfo
GET /services/apexrest/MobileVizArt/utils
GET /services/data/connect/proxy/HelloMSync
GET /services/data/{apiVersion}/query
GET /services/data/{apiVersion}/queryAll
GET /services/data/{apiVersion}/sobjects/{entityName}/describe
GET /services/data/{apiVersion}/sobjects/{entityName}/describe/layouts/{entityId}
PATCH /services/data/{apiVersion}/sobjects/Attachment/{entityId}
PATCH /services/data/{apiVersion}/sobjects/Attachment/{entityId}/{entityExternalId}
POST /Job
POST /RiskAssessment/JobRiskAssessments
POST /Task
POST /log
POST /notifications/registration/{handle}
POST /notifications/sending/{pns}
POST /services/apexrest/MobileVizArt/appReinstallNotification
POST /services/apexrest/MobileVizArt/checkObjectTypesToSynchronize
POST /services/apexrest/MobileVizArt/endCleanup
POST /services/apexrest/MobileVizArt/endUpload
POST /services/apexrest/MobileVizArt/getObjectPermissions
POST /services/apexrest/MobileVizArt/getRecordIds
POST /services/apexrest/MobileVizArt/getRecordsByIdsEnhanced
POST /services/apexrest/MobileVizArt/startDownload
POST /services/apexrest/MobileVizArt/syncRecordsToSfdc
POST /services/apexrest/MobileVizArt/syncTime
POST /services/apexrest/MobileVizArt/updateJobSyncTime
POST /services/apexrest/getRecordsOnDemand
POST /services/data/{apiVersion}/connect/proxy/app-analytics-logging
POST /services/data/{apiVersion}/sobjects/Attachment
POST /services/data/{apiVersion}/sobjects/ContentVersion
POST /services/data/{apiVersion}/sobjects/MobilePushServiceDevice
POST /services/data/{apiVersion}/sobjects/User/{entityId}
PUT /notifications/registration/{id}
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d606a2c9a1476cb247b7bde9b663afe4526e6d9195d
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths:
DELETE /services/data/{apiVersion}/sobjects/MobilePushServiceDevice/{id}
GET /Asset/LindeSerialNumber
GET /Asset/Tools
GET /AssetScrappingReason
GET /HcUtilities/CheckVersion
GET /HcUtilities/UserProfile
GET /Job/GetJobByFoJobId/{foJobId}
GET /Job/GetJobNoSignedReasons
GET /Job/GetJobsByTechnician
GET /Material/KitSearch
GET /Material/Search
GET /MaterialPoint/AssetDefaultDestination
GET /MaterialPoint/Search
GET /Patient/GetPatientByFoPatientId/{foPatientId}
GET /RiskAssessment
GET /RiskAssessment/{riskAssessmentId}
GET /WorkshopActivity
GET /WorkshopActivity/SparePartExchangeReason
GET /WorkshopActivity/SpareParts
GET /WorkshopActivity/Tools
GET /WorkshopActivityType
GET /api/Values
GET /api/Values/{id}
GET /asset/activeassets
GET /document
GET /document/Index
GET /notifications/registration/GetAll
GET /services/apexrest/MobileVizArt/countryTranslations
GET /services/apexrest/MobileVizArt/getCountrySettingnew/{countryName}
GET /services/apexrest/MobileVizArt/getTripJobsCount
GET /services/apexrest/MobileVizArt/getUserInfo
GET /services/apexrest/MobileVizArt/utils
GET /services/data/connect/proxy/HelloMSync
GET /services/data/{apiVersion}/query
GET /services/data/{apiVersion}/queryAll
GET /services/data/{apiVersion}/sobjects/{entityName}/describe
GET /services/data/{apiVersion}/sobjects/{entityName}/describe/layouts/{entityId}
PATCH /services/data/{apiVersion}/sobjects/Attachment/{entityId}
PATCH /services/data/{apiVersion}/sobjects/Attachment/{entityId}/{entityExternalId}
POST /Job
POST /RiskAssessment/JobRiskAssessments
POST /Task
POST /log
POST /notifications/registration/{handle}
POST /notifications/sending/{pns}
POST /services/apexrest/MobileVizArt/appReinstallNotification
POST /services/apexrest/MobileVizArt/checkObjectTypesToSynchronize
POST /services/apexrest/MobileVizArt/endCleanup
POST /services/apexrest/MobileVizArt/endUpload
POST /services/apexrest/MobileVizArt/getObjectPermissions
POST /services/apexrest/MobileVizArt/getRecordIds
POST /services/apexrest/MobileVizArt/getRecordsByIdsEnhanced
POST /services/apexrest/MobileVizArt/startDownload
POST /services/apexrest/MobileVizArt/syncRecordsToSfdc
POST /services/apexrest/MobileVizArt/syncTime
POST /services/apexrest/MobileVizArt/updateJobSyncTime
POST /services/apexrest/getRecordsOnDemand
POST /services/data/{apiVersion}/connect/proxy/app-analytics-logging
POST /services/data/{apiVersion}/sobjects/Attachment
POST /services/data/{apiVersion}/sobjects/ContentVersion
POST /services/data/{apiVersion}/sobjects/MobilePushServiceDevice
POST /services/data/{apiVersion}/sobjects/User/{entityId}
PUT /notifications/registration/{id}
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035491da2c34d351e21362f8c821f0889d1fd2a899098
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /services/data/{apiVersion}/sobjects/MobilePushServiceDevice/{id}
GET /Asset/LindeSerialNumber
GET /Asset/Tools
GET /AssetScrappingReason
GET /HcUtilities/CheckVersion
GET /HcUtilities/UserProfile
GET /Job/GetJobByFoJobId/{foJobId}
GET /Job/GetJobNoSignedReasons
GET /Job/GetJobsByTechnician
GET /Material/KitSearch
GET /Material/Search
GET /MaterialPoint/AssetDefaultDestination
GET /MaterialPoint/Search
GET /Patient/GetPatientByFoPatientId/{foPatientId}
GET /RiskAssessment
GET /RiskAssessment/{riskAssessmentId}
GET /WorkshopActivity
GET /WorkshopActivity/SparePartExchangeReason
GET /WorkshopActivity/SpareParts
GET /WorkshopActivity/Tools
GET /WorkshopActivityType
GET /api/Values
GET /api/Values/{id}
GET /asset/activeassets
GET /document
GET /document/Index
GET /notifications/registration/GetAll
GET /services/apexrest/MobileVizArt/countryTranslations
GET /services/apexrest/MobileVizArt/getCountrySettingnew/{countryName}
GET /services/apexrest/MobileVizArt/getTripJobsCount
GET /services/apexrest/MobileVizArt/getUserInfo
GET /services/apexrest/MobileVizArt/utils
GET /services/data/connect/proxy/HelloMSync
GET /services/data/{apiVersion}/query
GET /services/data/{apiVersion}/queryAll
GET /services/data/{apiVersion}/sobjects/{entityName}/describe
GET /services/data/{apiVersion}/sobjects/{entityName}/describe/layouts/{entityId}
PATCH /services/data/{apiVersion}/sobjects/Attachment/{entityId}
PATCH /services/data/{apiVersion}/sobjects/Attachment/{entityId}/{entityExternalId}
POST /Job
POST /RiskAssessment/JobRiskAssessments
POST /Task
POST /log
POST /notifications/registration/{handle}
POST /notifications/sending/{pns}
POST /services/apexrest/MobileVizArt/appReinstallNotification
POST /services/apexrest/MobileVizArt/checkObjectTypesToSynchronize
POST /services/apexrest/MobileVizArt/endCleanup
POST /services/apexrest/MobileVizArt/endUpload
POST /services/apexrest/MobileVizArt/getObjectPermissions
POST /services/apexrest/MobileVizArt/getRecordIds
POST /services/apexrest/MobileVizArt/getRecordsByIdsEnhanced
POST /services/apexrest/MobileVizArt/startDownload
POST /services/apexrest/MobileVizArt/syncRecordsToSfdc
POST /services/apexrest/MobileVizArt/syncTime
POST /services/apexrest/MobileVizArt/updateJobSyncTime
POST /services/apexrest/getRecordsOnDemand
POST /services/data/{apiVersion}/connect/proxy/app-analytics-logging
POST /services/data/{apiVersion}/sobjects/Attachment
POST /services/data/{apiVersion}/sobjects/ContentVersion
POST /services/data/{apiVersion}/sobjects/MobilePushServiceDevice
POST /services/data/{apiVersion}/sobjects/User/{entityId}
PUT /notifications/registration/{id}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549cd8eb320a589261db4afa4b494e2a06d2946ee52
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /Routyn/trip/{externalTripId}
DELETE /Routyn/vanloadstop/{externalVanLoadStopId}
GET /IWebCustomer/GetCustomerByCnp
GET /IWebCustomer/GetCustomerByDeviceSerialNumber
POST /CTI/Output/StartCall
POST /CardReadings/UpdateFileStatus
POST /EmailManagement/PublishEmail
POST /PatientProtocolAiEngine/CreateIntervention
POST /Routyn/trip
POST /Routyn/vanloadstop
POST /Sms/delivered-messages/{countryId}
POST /Sms/failed-messages/{countryId}
POST /Sms/messages/{countryId}
PUT /Routyn/address
PUT /Routyn/service
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549eb5cdc9bec58ceefda7dc52b0d9c3c9788f98b6d
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /WeatherForecast
GET /api/CheckDBConn
GET /api/CheckDBConn/{id}
GET /api/Get_AccessTypeCode
GET /api/Get_AreaLocMap/{id}
GET /api/Get_AvailableSpoofee
GET /api/Get_AvailableSpoofeeTest
GET /api/Get_BlackListHistView/{DriverId}
GET /api/Get_BloodGroupMaster
GET /api/Get_CoachDetailMasterListView
GET /api/Get_CoachDetailMasterListView/{DriverId}
GET /api/Get_CoachDetailsMaster/{id}
GET /api/Get_CoachDriverHistView/{DriverId}
GET /api/Get_CoachingSubjectDetails/{coachingId}
GET /api/Get_DriverId
GET /api/Get_DriverMaster
GET /api/Get_LOBMaster/{id}
GET /api/Get_LangMaster
GET /api/Get_LoginVal
GET /api/Get_ModuleMaster/{paramList}
GET /api/Get_ObservationDetails/{Id}
GET /api/Get_RRA_Master_Hdr
GET /api/Get_RRA_Master_Hdr/{Seq_No}
GET /api/Get_RRA_Master_Por_Map
GET /api/Get_RRA_PoR_Vehicle
GET /api/Get_RRA_PoR_Vehicle/{Seq_No}
GET /api/Get_RRA_RRA_Mstr
GET /api/Get_RRA_RRA_Mstr/{Seq_No}
GET /api/Get_RRA_RiskCategory
GET /api/Get_RRA_RiskCategory/{Seq_No}
GET /api/Get_RRA_Segment
GET /api/Get_RRA_Segment/{Seq_No}
GET /api/Get_RRA_Speed
GET /api/Get_RRA_Speed/{Seq_No}
GET /api/Get_RRA_UtilityValue/{id}/{code}/{country}
GET /api/Get_RoleAccessMap/{id}
GET /api/Get_RoleAccessMapAll/{subsubmodule_id}
GET /api/Get_RoleAssignment/{id}
GET /api/Get_RoleMaster
GET /api/Get_SafetyObservation
GET /api/V
GET /api/V/{id}
GET /api/Values
GET /api/Values/{id}
GET /api/Values1
GET /api/Values1/{id}
GET /api/ValuesController2
GET /api/ValuesController2/{id}
GET /api/driverado
GET /api/driverdapper
GET /api/email
POST /DriverMasterList
POST /api/Get_CoachingSubjectMaster
POST /api/Get_DFGetFatigueResult
POST /api/Get_RRA_Master_Por_Map_List_ByRRAId
POST /api/Get_RRA_PoR_Mstr
POST /api/Get_RRA_Utility
POST /api/Get_SafetyObservationListView
POST /api/Post_AllowedVehiclesMaster
POST /api/Post_AreaByCntryMaster
POST /api/Post_AreaLocMap
POST /api/Post_AreaMasterList
POST /api/Post_AreaMstrListStatus
POST /api/Post_BlackListReasonMaster
POST /api/Post_CheckDriverLicense
POST /api/Post_CoachDetailMaster
POST /api/Post_CoachDetailMasterList
POST /api/Post_CoachDetailMasterStatus
POST /api/Post_CoachEntityMasterData
POST /api/Post_CoachId
POST /api/Post_CoachMaster
POST /api/Post_CoachMasterData
POST /api/Post_CoachMasterList
POST /api/Post_CoachingEntityMasterData
POST /api/Post_CompanyMaster
POST /api/Post_ContractorMaster
POST /api/Post_CountryMaster
POST /api/Post_CountryMasterEdit
POST /api/Post_DFDeleteFatigueResults
POST /api/Post_DFInsertFatigueResult
POST /api/Post_DPGetDocRepo
POST /api/Post_DPSetDocRepo
POST /api/Post_DeleteAzureBlobStorage
POST /api/Post_DocTypeMaster
POST /api/Post_DocUploadRepo
POST /api/Post_DownloadAzureBlobStorage
POST /api/Post_DriverAttendance
POST /api/Post_DriverCoachReassign
POST /api/Post_DriverFatigueDistractionAlerts
POST /api/Post_DriverKMS
POST /api/Post_DriverMaster
POST /api/Post_DriverMasterData
POST /api/Post_DriverMasterList
POST /api/Post_DriverMasterStatus
POST /api/Post_DriverOBCViolations
POST /api/Post_DriverTypeMaster
POST /api/Post_EntityMaster
POST /api/Post_EntityMstrGet
POST /api/Post_FitnessResultTypeMaster
POST /api/Post_FitnessScreenTransGet
POST /api/Post_FitnessScreenTransPost
POST /api/Post_FitnessTestTypeMaster
POST /api/Post_GetUsers
POST /api/Post_IncidentMasterDriverAssign
POST /api/Post_IncidentMstrList
POST /api/Post_JobStatusMaster
POST /api/Post_LOBMaster
POST /api/Post_LangMaster
POST /api/Post_LocationByCntryMaster
POST /api/Post_LocationId
POST /api/Post_LocationMaster
POST /api/Post_LoginVal
POST /api/Post_ObsCatGetObservations
POST /api/Post_ObservationCategoryMaster
POST /api/Post_ObservationDetailsStatus
POST /api/Post_OtherLicensesMaster
POST /api/Post_PreviousEmployerGet
POST /api/Post_PreviousEmployerPost
POST /api/Post_RRA_Master_Hdr
POST /api/Post_RRA_PoR_Mstr
POST /api/Post_RRA_PoR_Vehicle
POST /api/Post_RRA_RRA_Mstr
POST /api/Post_RRA_RiskCategory
POST /api/Post_RRA_Search_PoR_Mstr
POST /api/Post_RRA_Segment
POST /api/Post_RRA_Speed
POST /api/Post_RRA_UtilityValue
POST /api/Post_RiskCategoryMaster
POST /api/Post_RoleAccessMap
POST /api/Post_RoleAccessMapStatus
POST /api/Post_RoleAccessMapSubSub
POST /api/Post_RoleAccessMasterList
POST /api/Post_RoleAssignment
POST /api/Post_RoleAssignmentList
POST /api/Post_RoleAssignmentStatus
POST /api/Post_RoleMaster
POST /api/Post_RoleMasterList
POST /api/Post_RoleMasterStatus
POST /api/Post_SafetyObservation
POST /api/Post_SafetyObservationList
POST /api/Post_SearchCoach
POST /api/Post_SearchLocByCntryMaster
POST /api/Post_SearchSegmentID
POST /api/Post_SubModuleMaster
POST /api/Post_SubSubModuleMaster
POST /api/Post_TransporterMaster
POST /api/Post_UploadAzureBlobStorage
POST /api/Post_UploadAzureFileStorage
POST /api/Post_UserLangPref
POST /api/Post_UserPolicy
POST /api/Post_VehicleTypeMaster
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa359d8fad0a3ec5814661a11090d0a61f30d0a61f3
GraphQL introspection enabled at /graphql Types: 318 (by kind: ENUM: 30, INPUT_OBJECT: 6, INTERFACE: 9, OBJECT: 259, SCALAR: 6, UNION: 8) Operations: - Query: RootQuery | fields: authorById, authors, citySearch, commentsById, contentById - Mutation: RootMutation | fields: competitionRequest, mailchimpListRequest, saveWebform, sendContactRequest, sendFormRequest
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549c5a353206c0397b6c3e0c909c3dda5e77a505d98
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /Banner/customComponent/{id}
GET /Banner/{appInstanceId}/components
GET /Banner/{appInstanceId}/customComponents
GET /OAuth/authorized
GET /OAuth/install
GET /OnboardingSteps/steps
GET /WixAdapter/scan/getScanResult
GET /WixAdapter/webhooks/ScanResultReady
GET /WixApi/instance/{appInstanceId}
GET /WixApi/instance/{appInstanceId}/activeScans
GET /WixApi/{appInstanceId}/bannerState
GET /WixScripts/cmpConfig/{appInstanceId}
GET /WixScripts/getScriptParam
GET /installations/showOnboardingBanner
GET /installations/supportedLanguages
GET /installations/v2/{appInstanceId}/translation
GET /installations/{appInstanceId}/billing-history
GET /installations/{appInstanceId}/configuration
GET /installations/{appInstanceId}/is-paid
GET /installations/{appInstanceId}/languages
GET /installations/{appInstanceId}/notifications
GET /installations/{appInstanceId}/translation
GET /installations/{appInstanceId}/translation/legal-notice
GET /installations/{appInstanceId}/usage
GET /instances/v1/instance/{appInstanceId}
GET /plans
GET /pricing/redirect
GET /wix-billing/checkout
GET /wix-billing/checkout-fixed-7-euro
GET /wix-billing/metered-billing-charges
POST /Authentication/refreshToken
POST /Authentication/signIn
POST /OnboardingSteps/show/{show}
POST /OnboardingSteps/steps/{stepId}/complete/{complete}
POST /WixAdapter/scan/start
POST /WixScripts/setScriptParam
POST /admin-ui/activescans/{appInstanceId}/clear
POST /admin-ui/installations/{appInstanceId}/reinstall
POST /admin-ui/notifications/global-upgrade
POST /events/clicks/upgrade-button
POST /events/pricing/page-opened
POST /installations
POST /installations/{appInstanceId}/notifications/read
POST /logs
POST /wix-billing/v1/charge-limit
POST /wix-billing/v1/charges
POST /wixWebhooks/instanceAppInstalled
POST /wixWebhooks/instanceAppRemoved
POST /wixWebhooks/paidPlanAutoRenewalCancelled
POST /wixWebhooks/paidPlanChanged
POST /wixWebhooks/paidPlanPurchased
POST /{appInstanceId}/recommendations/ignore
PUT /Banner/{appInstanceId}/customComponent
PUT /WixScripts/cmpConfig
PUT /WixScripts/consentConfiguration/{wixConsentConfigId}
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549c5a353206c0397b6c3e0c909c3dda5e701ba22b6
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /Banner/customComponent/{id}
GET /Banner/{appInstanceId}/components
GET /Banner/{appInstanceId}/customComponents
GET /OAuth/authorized
GET /OAuth/install
GET /OnboardingSteps/steps
GET /WixAdapter/scan/getScanResult
GET /WixAdapter/webhooks/ScanResultReady
GET /WixApi/instance/{appInstanceId}
GET /WixApi/instance/{appInstanceId}/activeScans
GET /WixApi/{appInstanceId}/bannerState
GET /WixScripts/cmpConfig/{appInstanceId}
GET /WixScripts/getScriptParam
GET /installations/showOnboardingBanner
GET /installations/supportedLanguages
GET /installations/v2/{appInstanceId}/translation
GET /installations/{appInstanceId}/billing-history
GET /installations/{appInstanceId}/configuration
GET /installations/{appInstanceId}/is-paid
GET /installations/{appInstanceId}/languages
GET /installations/{appInstanceId}/notifications
GET /installations/{appInstanceId}/translation
GET /installations/{appInstanceId}/translation/legal-notice
GET /installations/{appInstanceId}/usage
GET /instances/v1/instance/{appInstanceId}
GET /plans
GET /wix-billing/checkout
GET /wix-billing/checkout-fixed-7-euro
GET /wix-billing/metered-billing-charges
POST /Authentication/refreshToken
POST /Authentication/signIn
POST /OnboardingSteps/show/{show}
POST /OnboardingSteps/steps/{stepId}/complete/{complete}
POST /WixAdapter/scan/start
POST /WixScripts/setScriptParam
POST /admin-ui/activescans/{appInstanceId}/clear
POST /admin-ui/installations/{appInstanceId}/reinstall
POST /admin-ui/notifications/global-upgrade
POST /events/clicks/upgrade-button
POST /events/pricing/page-opened
POST /installations
POST /installations/{appInstanceId}/notifications/read
POST /logs
POST /wix-billing/v1/charge-limit
POST /wix-billing/v1/charges
POST /wixWebhooks/instanceAppInstalled
POST /wixWebhooks/instanceAppRemoved
POST /wixWebhooks/paidPlanAutoRenewalCancelled
POST /wixWebhooks/paidPlanChanged
POST /wixWebhooks/paidPlanPurchased
POST /{appInstanceId}/recommendations/ignore
PUT /Banner/{appInstanceId}/customComponent
PUT /WixScripts/cmpConfig
PUT /WixScripts/consentConfiguration/{wixConsentConfigId}
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa359d8fad0a3ec5814661a11090d0a61f30d0a61f3
GraphQL introspection enabled at /graphql Types: 318 (by kind: ENUM: 30, INPUT_OBJECT: 6, INTERFACE: 9, OBJECT: 259, SCALAR: 6, UNION: 8) Operations: - Query: RootQuery | fields: authorById, authors, citySearch, commentsById, contentById - Mutation: RootMutation | fields: competitionRequest, mailchimpListRequest, saveWebform, sendContactRequest, sendFormRequest
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa359d8fad0a3ec5814661a11090d0a61f30d0a61f3
GraphQL introspection enabled at /graphql Types: 318 (by kind: ENUM: 30, INPUT_OBJECT: 6, INTERFACE: 9, OBJECT: 259, SCALAR: 6, UNION: 8) Operations: - Query: RootQuery | fields: authorById, authors, citySearch, commentsById, contentById - Mutation: RootMutation | fields: competitionRequest, mailchimpListRequest, saveWebform, sendContactRequest, sendFormRequest
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035493b3b7350134270a9b13dbb76907f133ce347c355
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: GET / GET /EssoDeVoucher/Test POST /EssoDeVoucher/EmailExists POST /EssoDeVoucher/GetAccessToken POST /EssoDeVoucher/GetVoucher
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035496b513e27cae9c20b39825a868d257e75f829b03c
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/attachment
DELETE /api/attachment/delete-all
DELETE /api/azurestorage/delete-blobs-from-container
DELETE /api/azurestorage/delete-container
DELETE /api/data-retention/delete-blobs-and-attachment-metadata/{containerName}
DELETE /api/filelibrary
DELETE /api/filelibrary/{id}/attachments
DELETE /api/filelibrary/{id}/issues
DELETE /api/filelibrary/{id}/locations
DELETE /api/serviceorder/attachment/{key}
GET /api/attachment-removal/attachments
GET /api/attachment-removal/blob-names/{containerName}
GET /api/attachment-removal/container-names
GET /api/attachment-removal/file-library/all
GET /api/attachment/attachmentlimits
GET /api/attachment/attachmentlimitssteps
GET /api/azurestorage/attachment/{key}
GET /api/azurestorage/report/attachment/{filename}
GET /api/container-settings/storage-data
GET /api/container-settings/{unitGlobalId}
GET /api/filelibrary/all
GET /api/filelibrary/all/Locations
GET /api/filelibrary/all/issues
GET /api/filelibrary/{id}
GET /api/filelibrary/{id}/issue/attachments
GET /api/filelibrary/{id}/location/attachments
GET /api/metadata/attachment/{key}
GET /api/serviceorder/{id}/attachments
POST /api/attachment/attachment-count
POST /api/azurestorage/report/attachment
POST /api/azurestorage/upload-blobs
POST /api/container-settings/add-or-update-container-size-limit
POST /api/data-retention/attachments-metadata
POST /api/filelibrary/issue/attachments
POST /api/filelibrary/location/attachments
POST /api/serviceorder/attachments
PUT /api/filelibrary/issue/{id}/attachments
PUT /api/filelibrary/location/{id}/attachments
PUT /api/issue/{id}/file-library
PUT /api/location/{id}/file-library
PUT /api/metadata/{key}
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57d6f9573b
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=OTQ4MjM2NDgwNDI2
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e579406fc40
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NTM4NTYwNDU5OTQ3
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e5718923d76
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=OTQzNDI4NzUzMDU0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57d5344482
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=MzY0NDI0NzEwODA=
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e578d65c63a
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NjY5NDQwNzQwNzk=
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57b4652f69
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NzgxNzIyMTE4MzYz
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e5730883895
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=ODAyNDQxMDU1NDYy
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e579d9ddf49
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=MzM1NjQyNTEzODQw
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e5768fce2b5
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NjMzMTQ4MDQwNjkx
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e572d5c343c
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=MzQ2OTgyMjQ1OTg0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57816131bb
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NjA4MDM0NDU5NTEw
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57d9b05f9f
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=MjE4NTkyNTIwNw==
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e570d0e251b
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NjQ3NzAzNzc3NDg=
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa359d8fad0a3ec5814661a11090d0a61f30d0a61f3
GraphQL introspection enabled at /graphql Types: 318 (by kind: ENUM: 30, INPUT_OBJECT: 6, INTERFACE: 9, OBJECT: 259, SCALAR: 6, UNION: 8) Operations: - Query: RootQuery | fields: authorById, authors, citySearch, commentsById, contentById - Mutation: RootMutation | fields: competitionRequest, mailchimpListRequest, saveWebform, sendContactRequest, sendFormRequest
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57f0080ec2
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NDY4OTgwOTMwMDg5
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e5723413d23
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=MjA0Mzc1NDM4NzQ0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57a0f16b1b
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=ODExMjA5NjY1NDQw
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e5733d8715f
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NjA2MDMwODc3NDIy
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e5755459162
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NzYyODkxOTI0NDk3
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e5762b64abb
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=OTYwNjIyOTY1MTIy
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e571ef47fdb
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NDUwMjExNDI3MjU=
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e575a0dc544
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NjM4MjE5NDYxOTE=
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57bb6f48e9
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=MTQ1Nzc3Njk4MDk3
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57d132248c
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=ODY0MDMzNjkzMzE3
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e5778000552
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NDI3MjE3MzMxNjcx
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57bca09ae0
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=MTI3OTMxMzEyNjM3
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa359d8fad0a3ec5814661a11090d0a61f30d0a61f3
GraphQL introspection enabled at /graphql Types: 318 (by kind: ENUM: 30, INPUT_OBJECT: 6, INTERFACE: 9, OBJECT: 259, SCALAR: 6, UNION: 8) Operations: - Query: RootQuery | fields: authorById, authors, citySearch, commentsById, contentById - Mutation: RootMutation | fields: competitionRequest, mailchimpListRequest, saveWebform, sendContactRequest, sendFormRequest
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57a724447e
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=Mzg3MjI2NzMwMjAy
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e574245801a
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=MzA3ODcwMzg2Mzgx
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57c9f81418
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=Njk0MTE3MjYyMzI5
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57fc708fff
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NjAzMzIzMTYwNg==
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57e3bc1ac5
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=Mjg4Mjg0MjI4MTY1
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57b6891a43
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NjU5MjI0MTEwNTY3
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e5793517b35
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=Nzk1NTc2ODcyMTg1
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57450d2549
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=Mjk5Mjc4NjQ0OTQ3
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa359d8fad0a3ec5814661a11090d0a61f30d0a61f3
GraphQL introspection enabled at /graphql Types: 318 (by kind: ENUM: 30, INPUT_OBJECT: 6, INTERFACE: 9, OBJECT: 259, SCALAR: 6, UNION: 8) Operations: - Query: RootQuery | fields: authorById, authors, citySearch, commentsById, contentById - Mutation: RootMutation | fields: competitionRequest, mailchimpListRequest, saveWebform, sendContactRequest, sendFormRequest
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa359d8fad0a3ec5814661a11090d0a61f30d0a61f3
GraphQL introspection enabled at /graphql Types: 318 (by kind: ENUM: 30, INPUT_OBJECT: 6, INTERFACE: 9, OBJECT: 259, SCALAR: 6, UNION: 8) Operations: - Query: RootQuery | fields: authorById, authors, citySearch, commentsById, contentById - Mutation: RootMutation | fields: competitionRequest, mailchimpListRequest, saveWebform, sendContactRequest, sendFormRequest
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e570b65df21
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NTA1NjAxNzA0MjEy
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57e6745ff1
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=OTQwNjQ0MDM3NzY1
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e57e7faa5fe
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=NzY5NzE4MjI2MzMw
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa339812a78004d2e9c3def983e43366e5729524d21
GraphQL introspection enabled at /graphql Types: 168 (by kind: ENUM: 9, INTERFACE: 2, OBJECT: 148, SCALAR: 5, UNION: 4) Operations: - Query: RootQuery | fields: mostCommented, mostRead, mostShared, recommendations, recommendationsWithRelatedContent - Mutation: RootMutation | fields: addAlert, deleteAlert, deleteAlerts, editDefaults, updateAlert Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5) Readable stores: 1 integration (args: optional/default) : id=ODkyMDkzMDg2ODk2
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa359d8fad0a3ec5814661a11090d0a61f30d0a61f3
GraphQL introspection enabled at /graphql Types: 318 (by kind: ENUM: 30, INPUT_OBJECT: 6, INTERFACE: 9, OBJECT: 259, SCALAR: 6, UNION: 8) Operations: - Query: RootQuery | fields: authorById, authors, citySearch, commentsById, contentById - Mutation: RootMutation | fields: competitionRequest, mailchimpListRequest, saveWebform, sendContactRequest, sendFormRequest
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
cdn.graphql.dev.service.cash.ch 5 cdn.graphql.stage.service.tele.ch 4 cdn.graphql.stage.service.gaultmillau.ch 4 cdn.graphql.stage.service.handelszeitung.ch 4 cdn.graphql.stage.service.beobachter.ch 4 cdn.graphql.stage.service.illustre.ch 4 cdn.graphql.stage.service.schweizer-illustrierte.ch 4 cdn.graphql.stage.service.pme.ch 4 cdn.graphql.stage.service.cash.ch 4 api.mobilesync.hc.linde.com 3 wixapp-test.cookiebot.dev 2 api.update.gaultmillau.ch 2 api.update.handelszeitung.ch 2 api.update.pme.ch 2 api.update.beobachter.ch 2 api.preview.tele.ch 2 tst.api.mobilesync.hc.linde.com 2 so-attachment-api-global-cit.amadeus-hospitality.com 2 api.update.schweizer-illustrierte.ch 2 tst.distributionapps-driverprofile-api.linde.com 2 tst.distributionapps-itank-api.linde.com 1 api.performance.beobachter.ch 1 cms.ringiermedienschweiz.ch 1 api.trcservices.hc.linde.com 1 dev-esso-de-voucher.rapp-customers.co.uk 1