I haven't seen any examples (just code snippets), but I wouldn't call all unsanitized queries SQL injection vulnerabilities:
$sql = "SELECT * FROM inventory_item WHERE product_category_id='$pcid'";
The pcid var might have been checked/cleaned up before this line (might even be part of the same SO answer).-----
Obviously that doesn't mean this is very bad practise, especially at stackoverflow where you know people will just copy and paste your code.