The URL may be logged by the ISP, university/company or whoever is providing the connection, antivirus, windows recall, browser history... But IIRC passwords are send using cryptography if the site uses https.
It's not impossible that someone sees the URL, and if it's stored in an email the backups or local clients could store it plaintext, but I don't see how the URL is any more likely than the password to be sniffed during the connection itself