diff --git a/modules/backend/formwidgets/colorpicker/partials/_colorpicker.htm b/modules/backend/formwidgets/colorpicker/partials/_colorpicker.htm
index 9eb4d4e38..e1317e8fe 100644
--- a/modules/backend/formwidgets/colorpicker/partials/_colorpicker.htm
+++ b/modules/backend/formwidgets/colorpicker/partials/_colorpicker.htm
@@ -1,5 +1,5 @@
previewMode): ?>
-
= $value ?>
+ = e($value) ?>
-
+
@@ -30,7 +30,7 @@
type="hidden"
id="= $this->getId('input') ?>"
name="= $name ?>"
- value="= $value ?>" />
+ value="= e($value) ?>" />
diff --git a/modules/backend/formwidgets/mediafinder/partials/_file_single.htm b/modules/backend/formwidgets/mediafinder/partials/_file_single.htm
index 8a774a14a..1de373847 100644
--- a/modules/backend/formwidgets/mediafinder/partials/_file_single.htm
+++ b/modules/backend/formwidgets/mediafinder/partials/_file_single.htm
@@ -16,7 +16,7 @@
- = ltrim($value, '/') ?>
+ = e(ltrim($value, '/')) ?>