Drupal 11.x — End of Life

Active Actively exploited
EOL: Jul 7, 2027in 347d5 releases in this series33 CVEs

Drupal 11.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
11.4Jul 1, 2026Jan 1, 2027Jul 7, 202711.4.4Active
11.3Dec 17, 2025Jun 16, 2026Dec 16, 202611.3.16Active
11.2Jun 18, 2025Dec 10, 2025Jun 17, 202611.2.14EOL
11.1Dec 16, 2024Jun 18, 2025Dec 10, 202511.1.10EOL
11.0Aug 2, 2024Dec 16, 2024Jun 16, 202511.0.13EOL

CVEs affecting Drupal 11.x (33)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-55808MEDIUM5.40.16%11.0Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…Jul 10, 2026
CVE-2026-55808MEDIUM5.40.16%11.3Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…Jul 10, 2026
CVE-2026-55808MEDIUM5.40.16%11.2Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…Jul 10, 2026
CVE-2026-55808MEDIUM5.40.16%11.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…Jul 10, 2026
CVE-2026-55807LOW3.10.14%11.1Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af…Jul 10, 2026
CVE-2026-55807LOW3.10.14%11.0Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af…Jul 10, 2026
CVE-2026-55807LOW3.10.14%11.3Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af…Jul 10, 2026
CVE-2026-55807LOW3.10.14%11.2Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af…Jul 10, 2026
CVE-2026-55806MEDIUM5.90.21%11.0URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is…Jul 10, 2026
CVE-2026-55806MEDIUM5.90.21%11.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is…Jul 10, 2026
CVE-2026-55806MEDIUM5.90.21%11.2URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is…Jul 10, 2026
CVE-2026-55806MEDIUM5.90.21%11.3URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is…Jul 10, 2026
CVE-2026-55804MEDIUM5.90.21%11.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2026-55804MEDIUM5.90.21%11.3Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2026-55804MEDIUM5.90.21%11.2Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2026-55804MEDIUM5.90.21%11.0Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2026-55803MEDIUM5.90.21%11.2Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2026-55803MEDIUM5.90.21%11.3Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2026-55803MEDIUM5.90.21%11.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2026-55803MEDIUM5.90.21%11.0Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2026-9082CRITICAL9.888.32% KEV 11.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.888.32% KEV 11.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.888.32% KEV 11.1Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-9082CRITICAL9.888.32% KEV 11.0Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core…May 20, 2026
CVE-2026-6367MEDIUM6.10.20%11.3Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6366MEDIUM6.60.40%11.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.40%11.0Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.40%11.3Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6366MEDIUM6.60.40%11.2Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…May 19, 2026
CVE-2026-6365MEDIUM6.10.24%11.2Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.24%11.3Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.24%11.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026
CVE-2026-6365MEDIUM6.10.24%11.0Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…May 19, 2026

Frequently asked questions

Is Drupal 11 end of life?

Partially. Some Drupal 11.x releases have reached EOL. Check the version table above for the exact status of each sub-release.

What CVEs affect Drupal 11?

There are 33 CVEs tracked for Drupal 11.x, including 4 critical severity issues and 4 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Drupal 11 version?

The latest Drupal 11.x patch release is 11.4.4, released on July 15, 2026. Always run the latest patch to benefit from all security fixes.

When was Drupal 11 first released?

Drupal 11.0 was initially released on July 1, 2026. See the full version timeline in the table above.

Is it safe to run Drupal 11 in production?

Drupal 11 is still supported and safe for production use until July 7, 2027. Ensure you are running the latest patch version (11.4.4) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA