Drupal 7.x — End of Life

EOL Actively exploited
EOL: Jan 5, 20251 release in this series9 CVEs

Drupal 7.x reached end of life on Jan 5, 2025, 640 days ago, and no longer receives security fixes. The most recent release in this series is 7.103. 9 CVEs are tracked for this series, including 1 critical and 1 actively exploited according to CISA KEV. 5 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Drupal 8. See Drupal 8 →

Drupal 7.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
7LTSJan 5, 2011Nov 19, 2015Jan 5, 20257.103EOL

CVEs affecting Drupal 7.x (9)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-55808MEDIUM5.40.27%—7Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core…Jul 10, 2026
CVE-2026-55807LOW3.10.22%—7Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af…Jul 10, 2026
CVE-2026-55806MEDIUM5.90.33%—7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This is…Jul 10, 2026
CVE-2026-55804MEDIUM5.90.35%—7Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2026-55803MEDIUM5.90.35%—7Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow…Jul 10, 2026
CVE-2021-41184MEDIUM6.540.76%—7jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option…Oct 26, 2021
CVE-2021-41183MEDIUM6.58.53%—7jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text`…Oct 26, 2021
CVE-2021-41182MEDIUM6.539.36%—7jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` …Oct 26, 2021
CVE-2018-7602CRITICAL9.899.17% KEV 7A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows a…Jul 19, 2018

Drupal 7.x is EOL — migrate to Drupal 8.x

Drupal 8.x is the next major release. Plan your upgrade before Drupal 7.x stops receiving security patches.

See Drupal 8.x

Add a Drupal 7 EOL badge to your README

Show your users which Drupal version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Drupal 7 EOL status
[![Drupal 7 EOL status](https://eolcanary.com/badge/drupal/7.svg)](https://eolcanary.com/explore/drupal/7)

Frequently asked questions

Is Drupal 7 end of life?

Yes. All Drupal 7.x releases have reached end of life and no longer receive security patches. There are 9 known CVEs affecting Drupal 7.x, including 1 critical. Migrate to Drupal 8.x as soon as possible.

What CVEs affect Drupal 7?

There are 9 CVEs tracked for Drupal 7.x, including 1 critical severity issue and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Drupal 7 version?

The latest Drupal 7.x patch release is 7.103, released on December 4, 2024. Always run the latest patch to benefit from all security fixes.

How to migrate from Drupal 7 to Drupal 8?

To migrate from Drupal 7 to Drupal 8: (1) review the official Drupal 8 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Drupal 7 in production?

No. Drupal 7 has reached end of life and security vulnerabilities are no longer patched. Critically, 1 CVE affecting Drupal 7.x is in the CISA KEV catalog — meaning it is actively exploited in the wild. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA