If this is also a feature that already exists, then this post will be worthwhile for me.
As far as I can tell, there's not a button to manually invalidate all active sessions, and I'd highly recommend that. It's not a security vulnerability per se, but I'd say it's important to put in the queue.