History of SQL injection attacks in osm tags?

As a thought experiment: if we blocked problematic characters in the API using alternatives such as directional quotes throughout, how big a nuisance would it be?