I once read a story on Reddit about a payroll processor with an utterly unholy mess of a system. One day, they get a customer called "Select", and the entire system stopped working.
This isn't SQL, but HP printers' settings protocol uses XML and doesn't escape Wi-Fi SSIDs, so it breaks completely whenever any nearby SSID includes < or >. Which wouldn't be a massive problem, except for that Com Hem (our Comcast) has set their default SSID to COMHEM<(start of router MAC)>.
What do you mean by "IRL" ? SQL injections work every day, I think it's still the number one in the OWASP top 10.
There's the stories of people named Null that make various systems crash or reject them, probably because they coerce to strings before checking for a "null" value.
I had a classmate named «Faux» (which means “false” in French) and it caused many bugs with Excels spreadsheets in our school.
Just having those Unicode characters in his name is bad enough!
The Twitter account "Ominous Null" shares real-life examples of systems mishandling null values: