diff --git a/themes/bootstrap3/js/check_save_statuses.js b/themes/bootstrap3/js/check_save_statuses.js
index 1cf43788fd69cc31d35aca939209e731ac94e1e8..d1c9e6966c7c1f2707df6dceb5f9a94da78f73ef 100644
--- a/themes/bootstrap3/js/check_save_statuses.js
+++ b/themes/bootstrap3/js/check_save_statuses.js
@@ -32,7 +32,7 @@ function checkSaveStatuses() {
         var html = list.find('strong')[0].outerHTML+'<ul>';
         for (var i=0; i<response.data[sel].length; i++) {
           html += '<li><a href="' + response.data[sel][i].list_url + '">'
-                   + response.data[sel][i].list_title + '</a></li>';
+                   + htmlEncode(response.data[sel][i].list_title) + '</a></li>';
         }
         html += '</ul>';
         list.html(html).removeClass('hidden');