Also found a new type of SQL Injection on the site. Pretty nasty. It's a very complicated coding error, one I'm sure many other sites will be vulnerable to.
I may look over some old logs, see if anyone tried anything with it.
Having failed queries appear in the error log finally paid off though.