What is the HTB CWES?
The HTB Certified Web Exploitation Specialist (CWES) is Hack The Box's associate-level, hands-on web application penetration testing certification. It tests whether you can find, exploit, and chain web vulnerabilities (injection, XSS, file upload and inclusion, SSRF and SSTI, authentication and API flaws) and write them up in a professional report. Until October 1, 2025 it was called the Certified Bug Bounty Hunter (CBBH).
You earn it by completing the Web Penetration Tester Job-Role Path (20 modules, 279 sections, rated Medium) and then passing the exam. You have to finish 100% of the path before the exam unlocks.
The exam
The CWES exam runs for 7 days in a dedicated lab over VPN. A letter of engagement sets the scope, and you test several real-world web applications, submitting flags as you find them. HTB says only that you need a certain number of points plus a commercial-grade report. Reviewers report 10 flags and a pass mark of 8.
The report is due within the same 7 days. It has to be a commercial-grade report in English based on HTB's template (SysReptor's HTB template works too), uploaded as a PDF or ZIP of 20 MB or less, and submitting it ends your lab access. You get 2 attempts per voucher. The free retake has to start within 14 days of your feedback, and you only get it if you submitted a report the first time. Results arrive within 20 business days.
The 20 modules in order
- Web Fundamentals & Proxies: Web Requests · Introduction to Web Applications · Using Web Proxies
- Recon & Fuzzing: Information Gathering - Web Edition · Web Fuzzing · JavaScript Deobfuscation
- XSS & Injection: Cross-Site Scripting (XSS) · SQL Injection Fundamentals · SQLMap Essentials · Command Injections
- Uploads & Server-side: File Upload Attacks · Server-side Attacks
- Authentication Attacks: Login Brute Forcing · Broken Authentication
- Web Attacks, LFI & APIs: Web Attacks · File Inclusion · Attacking GraphQL · API Attacks
- Common Applications: Attacking Common Applications
- Reporting & Exam Prep: Bug Bounty Hunting Process
Top tips from people who passed
- Enumerate before you exploit. Map each app fully, then poke it by hand and read the responses. The exam labs are harder than the course. (0liverFlow, Corey Nicholson)
- Expect to chain. Passing takes exploit chaining and heavy enumeration beyond what the modules show. (Josh Wright)
- Set up the report before the exam. Load the SysReptor template before you connect, and write up each finding with screenshots as soon as you confirm it. (Sonal Chhen)
- Practice reporting beyond the path. The Bug Bounty Hunting Process module is short next to HTB's report bar, so do the Documentation & Reporting module too. (Alexandru-Ionuț Răducu)
- Get out of rabbit holes. If you're deep in one, the answer is probably simpler. Check payloads for one-character typos, and take breaks. (Malachi W., Z333RO)
The full list of tips is at the bottom of the Resource Library tab.
How to use this tracker
- Set your start date at the top. Every day's calendar date and your pace indicator are computed from it.
- Pick a timeline (30/40/50/75/110 days). They all cover the same curriculum, just packed into more or fewer days, and your progress carries across when you switch.
- Tick each task as you finish it. A day is marked complete when all its tasks are done.
- Use the Notes field on each day as a journal for payloads that worked, requests worth replaying, and things to revisit.
- All progress is saved in your browser. Use Export backup regularly to keep a copy.
Enumerate every application fully before you try to exploit it, and write up each finding the moment you confirm it. Reviewers say the exam labs are harder than the course and take chained attacks, so put real time into retired web boxes before you book it.
This is an independent study aid and is not affiliated with or endorsed by Hack The Box. Always confirm current module counts, exam format, and pricing on the official HTB Academy site.
Built on and inspired by mattrfield's coae-study-tracker.