I requested several hosting providers to disable mod_security or at least configure it less restrictive and most of them did. It helps to tell them you do NOT use Wordpress

Make sure to use the latest version of cmsms and tell the hosting provider you do.
The serialized_content argument mentioned in the ModSecurity log is indeed used by CMSMS core. So that should be allowed by Mod Security.