What is the HTB CWEE?
The HTB Certified Web Exploitation Expert (CWEE) is Hack The Box's expert-level, hands-on web exploitation certification. It covers advanced and mostly white-box web attacks: injection (XPath, LDAP, NoSQL, blind and advanced SQL), authentication attacks on JWT, OAuth and SAML, HTTP misconfigurations and request smuggling, deserialization, prototype pollution, race conditions, and parameter logic bugs, plus writing your own exploits and patches.
You earn it by completing the Senior Web Penetration Tester Job-Role Path (15 modules, 245 sections, rated Hard) and then passing the exam. You have to finish 100% of the path before the exam unlocks.
The exam
The CWEE exam runs for 10 days in a dedicated lab over VPN. You test several real-world applications using both black-box and white-box methods, reading source code and writing working exploits, and submit flags as you go. HTB says only that you need a minimum number of points plus a commercial-grade report. Reviewers report 6 flags across 3 apps, with a pass mark of 5 (about 90 of 100).
The report is due within the same 10 days. For CWEE it has to be raw Markdown files in a ZIP, not a PDF, password-protected per the exam instructions and 20 MB or less, and it has to include working exploits plus patches and remediation for each finding. You get 2 attempts per voucher. The free retake starts within 14 days of your feedback, and only if you submitted a report. Results arrive within 20 business days.
The 15 modules in order
- Injection & NoSQL: Injection Attacks · Introduction to NoSQL Injection
- Authentication Attacks: Attacking Authentication Mechanisms
- Client-Side & TLS: Advanced XSS and CSRF Exploitation · HTTPs/TLS Attacks
- HTTP Attacks: Abusing HTTP Misconfigurations · HTTP Attacks
- Blind SQLi & Whitebox: Blind SQL Injection · Intro to Whitebox Pentesting
- Modern & Deserialization: Modern Web Exploitation Techniques · Introduction to Deserialization Attacks · Whitebox Attacks
- Advanced SQLi & Logic Bugs: Advanced SQL Injections · Advanced Deserialization Attacks · Parameter Logic Bugs
Top tips from people who passed
- Read all the code. Much of the exam is white-box, so read every file, pinpoint the vulnerable lines, and explain why they're vulnerable. (Gabriel Vásquez, h4r0r)
- Chain bugs into flags. The Academy teaches single techniques; the exam makes you chain three or four into one flag. (Manesec, Gabriel Vásquez)
- Script your exploits. You write your own tooling here, so build and test scripts during the modules and don't skip the scripting sections. (Yudistira Arya, d415k)
- Give the report real time. It's raw Markdown with working exploits, patches, and a changelog, and reviewers spent 12 to 20 hours on it, so start it while you exploit. (d415k, Gabriel Vásquez)
- Watch for rabbit holes. Some paths exist only to waste time. Triage by likelihood, set up debugging early, and take breaks. (Khaled Nassar, Filip Kecman)
The full list of tips is at the bottom of the Resource Library tab.
How to use this tracker
- Set your start date at the top. Every day's calendar date and your pace indicator are computed from it.
- Pick a timeline (35/45/60/75/80 days). They all cover the same curriculum, just packed into more or fewer days, and your progress carries across when you switch.
- Tick each task as you finish it. A day is marked complete when all its tasks are done.
- Use the Notes field on each day as a journal for exploit scripts that worked, vulnerable code and line numbers, and things to revisit.
- All progress is saved in your browser. Use Export backup regularly to keep a copy.
This is an expert white-box exam, so treat source code as the main target: read all of it, pinpoint the vulnerable lines, and turn each finding into a working exploit and a patch. Start the Markdown report while you're still exploiting, since it needs working exploits and a changelog and takes many hours.
This is an independent study aid and is not affiliated with or endorsed by Hack The Box. Always confirm current module counts, exam format, and pricing on the official HTB Academy site.
Built on and inspired by mattrfield's coae-study-tracker.