One in twelve of
all security issues—in a period that begins when Flash was already on the decline and extends far beyond when Flash was at all relevant—were caused by
a single web browser plugin and you're trying to handwave that off as not a big deal? Adobe has the highest percentage of exploits listed there for any company that is not an OS vendor, and Flash has the most of any single product that is not Windows (in an era when XP was still supported!) or IE (which it ties with).
And, yeah, Flash did suck as an end-user experience. For a few years it seemed like every restaurant in existence had an all-Flash web presence, and, no, waiting for endless animations while wading through some entirely non-standard "rich media" experience, while listening to my laptop fans kick into overdrive, did not "surprise and delight" when I was just trying to find their hours and a menu. It was absolutely infuriating.
This is ignoring that one of the major malware vectors that wasn't a zero-day at the time was to just put up a webpage claiming that Flash was out of date, and then linking a fake updater. Sure, that wasn't entirely Adobe's fault, but if they'd done a better job of keeping it up to date on their own it would have been an awful lot less believable to end users.