CWEE Exam Prep & Study Resources

Hack The Box certification · 2 products

HTB Certified Web Exploitation Expert

Study materials for CWEE

Frequently asked questions

What is HTB CWEE?

CWEE (Certified Web Exploitation Expert) is Hack The Box's advanced web application security certification, targeting complex vulnerability chains, modern web framework exploitation, and techniques that go well beyond the OWASP Top 10. It is designed for senior web penetration testers and application security specialists who want to validate expert-level web exploitation skills. CWEE covers contemporary attack techniques against modern web stacks including JavaScript frameworks, GraphQL APIs, and sophisticated server-side vulnerabilities requiring deep technical understanding.

How hard is HTB CWEE?

CWEE is among HTB's hardest certifications and is positioned at the expert level of their web security track. The exam goes well beyond common OWASP vulnerabilities to cover prototype pollution, advanced deserialization attack chains, complex multi-step injection sequences, and WAF bypass techniques. Candidates need strong JavaScript knowledge, understanding of modern web framework internals, and the ability to develop custom exploitation automation. Even experienced web penetration testers frequently report that CWEE requires significant dedicated preparation.

CWEE vs OSWE, how do they compare?

Both CWEE and OSWE are advanced web security certifications but with different approaches. OSWE uses a white-box methodology focused on source code review across older web application frameworks (PHP, Java, Python), requiring candidates to read code and develop exploit chains from source analysis. CWEE takes a more black-box approach targeting modern web stacks and contemporary attack techniques including prototype pollution, GraphQL injection, and advanced SSRF chains. CWEE is generally considered more current in its coverage of modern web technologies, while OSWE remains highly respected for its code review depth.

What topics does CWEE cover?

CWEE covers advanced and modern web exploitation techniques. Topics include JavaScript prototype pollution, advanced cross-site scripting chains, GraphQL injection and introspection abuse, OAuth 2.0 and OpenID Connect misconfigurations, advanced server-side request forgery chains for internal service exploitation, Java and Python deserialization attacks, race condition exploitation, HTTP request smuggling in complex proxy configurations, and server-side template injection across multiple modern frameworks. The focus is on understanding the root cause of each vulnerability class and developing reliable exploit chains.

Prerequisites for CWEE?

CBBH or equivalent OSWA-level web application security skills are the recommended baseline for CWEE. Strong JavaScript knowledge is essential since many of the techniques covered, particularly prototype pollution and advanced XSS chains, require deep understanding of JavaScript runtime behavior. Familiarity with modern web frameworks and API architectures is necessary. Experience with Burp Suite Pro and its extensions is beneficial. Candidates should be comfortable exploiting common web vulnerabilities quickly before spending preparation time on the advanced topics that CWEE introduces.

Is CWEE worth it?

Yes for application security specialists, senior web penetration testers, and professionals who focus specifically on web exploitation. CWEE demonstrates cutting-edge web security skills that are directly applicable in advanced bug bounty hunting, application security consulting, and penetration testing engagements involving modern web applications. The techniques covered align with contemporary attack research and real-world vulnerability disclosures, making CWEE knowledge practically relevant rather than focused on outdated vulnerability classes. For those serious about web security specialization, CWEE is a strong differentiating credential.

Related

All Hack The Box certifications · Browse cheatsheets