CWES Study Plan
The rebranded, expanded successor to HTB CBBH. A free, day-by-day CWES schedule built from the official HTB Academy: Web Penetration Tester Job Role Path syllabus, scaled to your exam date and weekly hours.
- Approx. cost
- $490–$1,260
- Difficulty
- ♥♥♥♥♥
- Study time
- about 191h
- Start level
- Junior
> How long does CWES take?
The plan assumes about 191 study hours. Here is how that stretches across different weekly schedules.
| Hours per week | Time to finish |
|---|---|
| 5 hours | about 39 weeks (9.0 months) |
| 10 hours | about 20 weeks (4.6 months) |
| 15 hours | about 13 weeks (3.0 months) |
| 20 hours | about 10 weeks (2.3 months) |
| 30 hours | about 7 weeks (1.6 months) |
> CWES exam format
Hack The Box · HTB Academy: Web Penetration Tester Job Role Path
- Hands-on web penetration test against multiple real-world applications
- Must complete 100% of the Web Penetration Tester job-role path first
- No multiple-choice questions; a letter of engagement sets the scope
- Commercial-grade report required to pass
- Successor to the original HTB Certified Bug Bounty Hunter (CBBH)
> CWES syllabus and study hours
Every topic in the plan, in order, with its baseline hours. The planner shrinks or stretches these to fit your dates.
Web Fundamentals
Requests, proxies, and reconnaissance before exploitation.
- Web Requests4h · learn
- Introduction to Web Applications9h · learn
- Using Web Proxies8h · learn
- Information Gathering - Web Edition10h · learn
Fuzzing & Injection
The classic injection vulnerability classes.
- Web Fuzzing7h · learn
- JavaScript Deobfuscation6h · learn
- Cross-Site Scripting (XSS)6h · learn
- SQL Injection Fundamentals9h · learn
- SQLMap Essentials6h · learn
- Command Injections7h · learn
Server-Side Exploitation
Upload flaws, backend logic, and authentication weaknesses.
- File Upload Attacks6h · learn
- Server-side Attacks10h · learn
- Login Brute Forcing7h · learn
- Broken Authentication8h · learn
- Web Attacks10h · learn
- File Inclusion6h · learn
APIs & Real Applications
Modern API surfaces and real CMS/application targets.
- Attacking GraphQL5h · learn
- API Attacks7h · learn
- Attacking Common Applications18h · learn
- Bug Bounty Hunting Process3h · learn
Training Grounds
Reinforce the path with real targets.
- Web-focused HTB boxes16h · lab
- Practice on a real bug bounty program10h · lab
Final Boss Prep
Methodology and a full-length dry run.
- Build a web recon & exploitation checklist5h · review
- Timed mock exam on unfamiliar apps8h · review
> Where to practise for CWES
Each task in your plan lists practice labs for its own topic. These are the best places to put in extra hands-on hours:
- All Web Security Academy labs (PortSwigger)
- Mystery lab challenge (PortSwigger)
- Juice Shop (practice app) (OWASP)
> CWES exam-day checklist
General logistics for exam week. The official exam guide always takes priority if it differs.
One to two weeks before
- Schedule your exam and add the start time, time zone and deadline to your calendar
- Read the official exam guide end to end: rules, allowed and banned tools, and what counts as proof
- Practise on unfamiliar web apps under time pressure
- Complete a full-length timed practice run on your exam setup
- Finalize your note-taking setup and templates (see the notes starter below)
- Build and review your cheat sheets and command references
- Arrange time off, tell people you will be unavailable, and plan your meals ahead
Machine and network
- Charge and test a backup device or phone hotspot, and know how to contact support if your connection drops
- Plug in your laptop and turn off sleep, updates and notifications for the exam
- Test the VPN or lab connection early and know how to reconnect after a drop
- Update your attack VM, take a clean snapshot and keep a spare
- Install and test every tool you plan to use, and check none of them are banned
- Test your screenshot hotkeys and make sure you have plenty of free disk space
During the exam
- Sleep well the night before, and skip last-minute cramming
- Prepare food and water, and set timers for break reminders
- Read the brief and scope carefully before you touch anything
- Write notes and capture proof as you go, not at the end
- Time-box each target and move on when stuck. You can come back later
Report and submission
- Copy your report template and fill in the easy parts (scope, methodology) while you work
- Check every finding has reproducible steps and screenshots
- Proofread: could someone else follow each step?
- Export in the exact format and naming the exam guide requires
- Submit with a buffer before the deadline and confirm it was received
Suggested exam-day rhythm
- Before you start. Check how long the exam window is and work backwards from the deadline.
- Daily. Fixed working blocks of about 90 minutes, a 10-minute break after each, and a proper stop at night.
- Each day. Update notes, list your next ideas and back up your evidence.
- Near the end. Stop new attacks early enough to verify findings and write the report.
- Submission. Submit with a buffer before the deadline and confirm it was received.
▶ Open the interactive CWES exam kit
The kit lets you tick items off, download a notes starter and report template, and see a readiness score from your plan progress.
> Passed CWES with PWN PATH
No CWES debriefs yet
Passed a cert? A short debrief helps the next learner plan their own run, and it only takes a couple of minutes.
▶ Share my debriefDebriefs are self-reported. See all pass stories.
> Frequently asked questions
How long does it take to prepare for CWES?
PWN PATH builds the CWES plan on about 191 study hours. At 10 hours a week that is roughly 20 weeks, and at 20 hours a week roughly 10 weeks. Your own timeline depends on how much of the material you already know.
What is the CWES exam like?
Hands-on web penetration test against multiple real-world applications. Must complete 100% of the Web Penetration Tester job-role path first. No multiple-choice questions; a letter of engagement sets the scope. Commercial-grade report required to pass. Successor to the original HTB Certified Bug Bounty Hunter (CBBH).
How hard is CWES?
We rate CWES 2 out of 5. It suits people who want hands-on web exploitation and bug bounty skills on a budget. Basic HTTP and Linux.
How much does CWES cost?
HTB Academy subscription plus a $210 exam voucher. Silver Annual is about $490–550 with a voucher included; some advanced paths need Gold. Prices are approximate, in US dollars unless a currency is shown, and change often. Confirm with the vendor before you buy.
What should I study first for CWES?
Start with the "Web Fundamentals" phase: Web Requests, Introduction to Web Applications, Using Web Proxies. The planner puts topics in a sensible order and scales the hours to the time you have.
What are the prerequisites for CWES?
Basic HTTP and Linux.
What should I do the week before the CWES exam?
Re-read the official exam guide for rules and banned tools, test your machine, network and VPN or lab connection, finish a full timed practice run, finalize your notes and cheat sheets, and plan your meals, breaks and sleep. The exam-day checklist on this page covers it step by step.
How should I handle breaks and sleep during the CWES exam?
Before you start: Check how long the exam window is and work backwards from the deadline. Daily: Fixed working blocks of about 90 minutes, a 10-minute break after each, and a proper stop at night. Each day: Update notes, list your next ideas and back up your evidence. Near the end: Stop new attacks early enough to verify findings and write the report.
What should I take after CWES?
Common next steps are CWEE, BSCP. See the roadmap to compare them.
Is the PWN PATH study planner free?
Yes. There are no accounts and no sign-up. Your plan and progress are saved in your browser, and you can export a backup file, add the schedule to your calendar or print it.
> Plan your path
Where it leads:
More in web application security:
Not sure CWES is right for you? Take the one-minute cert quiz.