By mod_security's design, it's heuristic based so it can trigger plenty of false positives. It really depends on the rule set used by your host. The more strict the rules, the more likely there's going to be a problem. Disabling certain mod_security rules to run XF is not uncommon.