Stop letting Mailman subscribers choose their own password -- it's stored insecurely and sent to them by email in clear text. Even though Mailman displays "Do not use a valuable password as it will occasionally be emailed back to you in cleartext" message, nobody reads messages.
Treat these "not valuable passwords" as good-to-have but not required to be 100% secure tokens and generate them automatically and include them into the links.