Very different case from storing them in plain text in the database or elsewhere.
Passwords stored unhashed in a database fail catastrophically and irrevocably against a point-compromise attacker. Hashed passwords, validated using plaintext passwords, only leak all passwords entered since the moment of compromise.
if the credentials are in the logs they'll harvest those to attempt logins on other sites.
To be clear: a properly designed system can and should operate without the server ever knowing the plaintext password.
But that would require a canonical and secure (i.e. not (only) controlled by server-fetched code) way of client-side password preprocessing, and if you have that, you can just as well use a PAKE, modern instances of which have all of these nice properties and more.