Only for weak passwords. Strong (80-bit plus) passwords are still safe, even with unsalted MD5. Too bad people are really bad at choosing passwords.
Ever since I switched to a password manager, I've always made sure that the length of it is the maximum length that the site will accept.
I am getting pretty pissed with the sites that have ridiculous "security" schemes like 1 capital letter, 1 one number, 1 special character, must rotate every three months...but will only allow a password between 8-12 characters long.