diff --git a/include/class.forms.php b/include/class.forms.php
index e178444696cbd82bff4a0dbe52e62243559f938f..43d1416ffa5c743bdf2b362ddfa8c0449836f5bf 100644
--- a/include/class.forms.php
+++ b/include/class.forms.php
@@ -1920,7 +1920,7 @@ class ChoicesWidget extends Widget {
                     continue; ?>
                 <option value="<?php echo $key; ?>" <?php
                     if (isset($values[$key])) echo 'selected="selected"';
-                ?>><?php echo $name; ?></option>
+                ?>><?php echo Format::htmlchars($name); ?></option>
             <?php } ?>
         </select>
         <?php