If you searched for the HTB CWES and found pages about the CBBH, you are in the right place: the HTB Certified Web Exploitation Specialist (CWES) is the exam formerly known as the Certified Bug Bounty Hunter (CBBH). Hack The Box's own materials now describe it as measuring proficiency in professional bug bounty hunting and web application penetration testing.
The exam gives you seven days to attack a set of web targets and then hand in a written report. This post covers what Hack The Box officially publishes, what it does not, and an eight-week plan built around the path you must finish before you can sit it.
What the HTB CWES Exam Is
The CWES validates intermediate competence in finding security risks in web applications, API architectures and backend services. It is a hands-on practical, not a multiple-choice test.
| Detail | HTB CWES |
|---|---|
| Former name | HTB Certified Bug Bounty Hunter (CBBH) |
| Exam window | 7 days from starting |
| Prerequisite | 100% completion of the CWES job-role path, plus an exam voucher |
| Deliverable | Commercial-grade penetration testing report, in English |
| Report format | Unencrypted PDF or ZIP, maximum 20MB |
| Marking time | Up to 20 business days |
| Retake | One automatic second attempt if you submitted a report on the first |
Hack The Box's help centre lists the points threshold for some certifications but not for the CWES, and it does not state a voucher price in the pages we checked. Candidate write-ups commonly say you need roughly eight of ten flags, but that is community reporting rather than a published figure, so confirm the current requirement on your Academy exam page before you plan around it.
Exam Tip: The report is part of the pass. Hack The Box asks for a detailed, commercial-grade report, and candidate reviews regularly name a weak report as the reason for a fail. Treat it as a deliverable, not an afterthought.
The 20-Module Path You Must Finish First
You cannot book the exam until the Web Penetration Tester job-role path shows 100% complete. It has 20 modules, graded from Fundamental to Medium difficulty:
- Web Requests
- Introduction to Web Applications
- Using Web Proxies
- Information Gathering - Web Edition
- Web Fuzzing
- JavaScript Deobfuscation
- Cross-Site Scripting (XSS)
- SQL Injection Fundamentals
- SQLMap Essentials
- Command Injections
- File Upload Attacks
- Server-side Attacks
- Login Brute Forcing
- Broken Authentication
- Web Attacks
- File Inclusion
- Attacking GraphQL
- API Attacks
- Attacking Common Applications
- Bug Bounty Hunting Process
The first six modules are groundwork. The injection, upload, inclusion and authentication modules are where most exam findings come from.
An 8-Week Study Plan
This plan assumes about ten hours a week. Compress it if you already work in application security.
Weeks 1 and 2: foundations and recon
Work through modules 1 to 6. Get fluent in an intercepting proxy, because everything later depends on it. Build a habit of writing down every request you modify and why.
Weeks 3 and 4: injection
Cover XSS, SQL injection, SQLMap, command injection and file uploads (modules 7 to 11). Do the module skills assessments without looking at your notes first. If you cannot finish one cold, repeat the module.
Weeks 5 and 6: server-side, authentication and APIs
Finish modules 12 to 18. Pay attention to chaining. The exam is described by candidates as rewarding people who combine a low-impact bug with a second step, not people who find one isolated flaw.
Week 7: the final modules and a dry run
Complete Attacking Common Applications and the Bug Bounty Hunting Process. Then write a practice report for a lab box you have already solved, using the same structure you will use in the exam: summary, finding, impact, evidence, remediation.
Week 8: rest and logistics
Test your VPN or Pwnbox setup, organise your notes by vulnerability class and sort out the days you will have free. Do not cram a new topic.
How to Spend the Seven Days
Seven days is generous for the targets and tight for the report. A sensible split:
- Days 1 to 4: enumerate every target thoroughly and collect flags. Screenshot evidence as you go.
- Days 5 and 6: return to anything unresolved, then stop attacking.
- Day 7: finish the report, check every finding has reproduction steps, and submit.
Take notes in the report format from the first hour. Rebuilding evidence on day seven is how reports end up thin.
If You Fail the First Attempt
If your first attempt did not pass and you submitted a report, Hack The Box gives you one automatic second attempt. You have 14 days from receiving feedback to start it. Read the feedback closely, because it tells you which areas to fix.
Where This Fits in Your Path
The CWES is a web-application specialism. If you want broader network and Active Directory coverage, read our HTB CPTS study plan next, and see what to take after OSCP for how the lab certifications compare. If you want the source-code-review route into web security, the OffSec OSWE plan covers it.
CertCrush does not offer a course for the HTB exam itself. If you want structured pentesting fundamentals first (methodology, scoping, reporting and the attack classes above), the CompTIA PenTest+ course is the closest fit, though it prepares you for PenTest+, not the CWES.
Frequently Asked Questions
What does HTB CWES stand for?
HTB CWES stands for Hack The Box Certified Web Exploitation Specialist. It is the current name for the exam previously called the Certified Bug Bounty Hunter, or CBBH.
How long is the HTB CWES exam?
You have seven days from starting the exam to complete the practical work and submit your report. Marking can then take up to 20 business days.
Is the HTB CWES the same as the CBBH?
Candidate reviews and Hack The Box's own listings treat them as the same certification under a new name. Search results for both terms point at the same material, so a CBBH study resource is still useful if its content matches the 20-module path above.
Can I retake the HTB CWES?
If you fail the first attempt after submitting a report, Hack The Box grants one automatic second attempt. You must start it within 14 days of receiving your feedback.
Ready to Start Practising?
A web-exploitation exam rewards methodical habits more than clever tricks. Build the fundamentals first, then take them into the lab. Create a free CertCrush account to practise exam-style questions on penetration testing concepts while you work through the path.
