Where Does Drupal Store Uploaded Files?
Drupal stores uploads in sites/default/files under the web root, with config in settings.php beside it. Self-hosted paths plus private files notes.
Last updated
Drupal keeps user uploads in a files directory inside each site folder, normally sites/default/files under the web root. Config sits beside it in settings.php. Multisite installs repeat the pattern per site, so site two uses sites/example.com/files instead.
Uploads and database travel together. The files directory without a database dump is orphaned blobs, and a database without files is broken images. Back up both or back up neither. Drush commands respect the same files directory, so command line imports land where the web UI expects them.
Where Drupal stores this, by platform
<web-root>/sites/default/files
Web server writable upload store. settings.php beside it decides public versus private. Multi-site installs repeat per site folder. Exact web root varies (/var/www/html, /var/www/drupal) by distro and host.
Frequently asked questions
What if my uploads are not in sites/default/files?
Check the file system path in Configuration, Media, File system. Admins can move it outside the web root for security, in which case uploads never sit in sites/default/files at all.
How do I back up a Drupal site?
Copy the files directory plus a database dump. Code comes from git or composer, so files plus database is the complete backup. One without the other restores nothing usable.
Notice an outdated path? Let us know.