The whole point of my post, which you seem to have completely and utterly missed, was that you don't need 0-days for exploiting Pale Moon. Every single Mozilla CVE published from Firefox 38 to Firefox 50 is potential issue for it. The amount of 0-days in there is exceedingly low, but amount of CVE is very high, because Mozilla publishes CVEs for security bugs they find themselves. AFAIK Google also does this, but Microsoft doesn't.
This isn't FUD. You can literally go read the list:
https://www.mozilla.org/en-US/security/known-vulnerabilities...
I count over 174 fixed vulnerabilities and stopped at version 48. Yes, some of these might not apply to Pale Moon because they're new vulnerabilities or it has the relevant feature disabled. You think anyone did the work to go through them all? Let alone backport the ones that are relevant?
Mozilla used to do this work for Pale Moon by virtue of still backporting the most important ones (i.e. not all) to ESR38. Not any more. Good luck!
the vast majority are for things like WebRTC, WebGl, and other attack surfaces that Pale Moon intentionally avoids
Pale Moon supports WebGL nowadays. It's needed for a few things like Google Maps to not suck. Of course, the implementation is outdated, which is perhaps what made you think it's not there...