This is just not true. SQL injection attacks account for between 7-30% of web application attacks:
https://www.esecurityplanet.com/network-security/most-common...
https://www.ptsecurity.com/ww-en/analytics/web-application-a...
https://www.esecurityplanet.com/network-security/most-common...
https://www.ptsecurity.com/ww-en/analytics/web-application-a...
Though having worked as a penetration tester I can say that, while rare, it was certainly not unheard of for a client's web application to be vulnerable to SQL injection. And this is for clients who are willing to spend several $1000s on a penetration test for their website - imagine what its like for people who don't give a second thought to the security of their site.