Rubedo CMS through 3.4.0 contains a directory traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.
View the template here CVE-2018-16836.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2018-16836