- 4.7.13 and earlier
- 4.6.23 and earlier
When displaying entity reference fields, the labels were not properly being escaped.
Update to the latest version of CiviCRM
If you cannot upgrade apply the following patch https://github.com/civicrm/civicrm-core/pull/9482/files
Coleman Watts for raising the issue and providing a fix.