Drupal 7.x — End of Life
EOL Actively exploitedDrupal 7.x reached end of life on Jan 5, 2025, 640 days ago, and no longer receives security fixes. The most recent release in this series is 7.103. 9 CVEs are tracked for this series, including 1 critical and 1 actively exploited according to CISA KEV. 5 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Drupal 8. See Drupal 8 →
Drupal 7.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 7LTS | Jan 5, 2011 | Nov 19, 2015 | Jan 5, 2025 | 7.103 | EOL |
CVEs affecting Drupal 7.x (9)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-55808 | MEDIUM | 5.4 | 0.27% | — | 7 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core… | Jul 10, 2026 |
| CVE-2026-55807 | LOW | 3.1 | 0.22% | — | 7 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af… | Jul 10, 2026 |
| CVE-2026-55806 | MEDIUM | 5.9 | 0.33% | — | 7 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is… | Jul 10, 2026 |
| CVE-2026-55804 | MEDIUM | 5.9 | 0.35% | — | 7 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow… | Jul 10, 2026 |
| CVE-2026-55803 | MEDIUM | 5.9 | 0.35% | — | 7 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow… | Jul 10, 2026 |
| CVE-2021-41184 | MEDIUM | 6.5 | 40.76% | — | 7 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option… | Oct 26, 2021 |
| CVE-2021-41183 | MEDIUM | 6.5 | 8.53% | — | 7 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text`… | Oct 26, 2021 |
| CVE-2021-41182 | MEDIUM | 6.5 | 39.36% | — | 7 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` … | Oct 26, 2021 |
| CVE-2018-7602 | CRITICAL | 9.8 | 99.17% | KEV | 7 | A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows a… | Jul 19, 2018 |
Drupal 7.x is EOL — migrate to Drupal 8.x
Drupal 8.x is the next major release. Plan your upgrade before Drupal 7.x stops receiving security patches.
Add a Drupal 7 EOL badge to your README
Show your users which Drupal version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/drupal/7)Frequently asked questions
Is Drupal 7 end of life?
Yes. All Drupal 7.x releases have reached end of life and no longer receive security patches. There are 9 known CVEs affecting Drupal 7.x, including 1 critical. Migrate to Drupal 8.x as soon as possible.
What CVEs affect Drupal 7?
There are 9 CVEs tracked for Drupal 7.x, including 1 critical severity issue and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.
What is the latest Drupal 7 version?
The latest Drupal 7.x patch release is 7.103, released on December 4, 2024. Always run the latest patch to benefit from all security fixes.
How to migrate from Drupal 7 to Drupal 8?
To migrate from Drupal 7 to Drupal 8: (1) review the official Drupal 8 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Drupal 7 in production?
No. Drupal 7 has reached end of life and security vulnerabilities are no longer patched. Critically, 1 CVE affecting Drupal 7.x is in the CISA KEV catalog — meaning it is actively exploited in the wild. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
